CVE-2008-0314
clamav
EPSS 24.0%
Description
Heap-based buffer overflow in spin.c in libclamav in ClamAV 0.92.1 allows remote attackers to execute arbitrary code via a crafted PeSpin packed PE binary with a modified length value.
How to fix CVE-2008-0314
To remediate CVE-2008-0314, upgrade the affected package to a fixed version below.
- Debian/clamav—upgrade to 0.92.1~dfsg2-1 or later
- Debian/clamav—upgrade to 0.90.1dfsg-3etch11 or later
Is CVE-2008-0314 being exploited?
Moderate — EPSS is 24.0%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 0.92.1~dfsg2-1
- from 0, < 0.90.1dfsg-3etch11