CVE-2011-1003
EPSS 9.4%
Description
Double free vulnerability in the vba_read_project_strings function in vba_extract.c in libclamav in ClamAV before 0.97 might allow remote attackers to execute arbitrary code via crafted Visual Basic for Applications (VBA) data in a Microsoft Office document. NOTE: some of these details are obtained from third party information.
How to fix CVE-2011-1003
To remediate CVE-2011-1003, upgrade the affected package to a fixed version below.
- Debian/clamav—upgrade to 0.97+dfsg-1 or later
Is CVE-2011-1003 being exploited?
Moderate — EPSS is 9.4%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 0.97+dfsg-1