← Back

CVE-2010-1311

nvd nist
Published: Apr 8, 2010Modified: Apr 29, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The qtm_decompress function in libclamav/mspack.c in ClamAV before 0.96 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted CAB archive that uses the Quantum (aka .Q) compression format. NOTE: some of these details are obtained from third party information.

Affected (96)

Products: Clamav: Clamav · Clamavs: Clamav
1 product
Clamav
1 product
Clamav
Configuration A
96 vulnerable
Vulnerable SoftwareAffected Versions
Clamav
Up to 0.96
Version 0.01
Version 0.02
Version 0.03
Version 0.05
Version 0.10
Version 0.12
Version 0.13
Version 0.14
Version 0.14 pre
Version 0.15
Version 0.20
Version 0.21
Version 0.22
Version 0.23
Version 0.24
Version 0.3
Version 0.51
Version 0.52
Version 0.53
Version 0.54
Version 0.60
Version 0.60p
Version 0.65
Version 0.66
Version 0.67-1
Version 0.67
Version 0.68.1
Version 0.68
Version 0.70
Version 0.70 rc
Version 0.71
Version 0.72
Version 0.73
Version 0.74
Version 0.75.1
Version 0.75
Version 0.80
Version 0.80 rc2
Version 0.80 rc3
Version 0.80 rc4
Version 0.80 rc
Version 0.81
Version 0.82
Version 0.83
Version 0.84
Version 0.84 rc1
Version 0.84 rc2
Version 0.85.1
Version 0.85
Version 0.86.1
Version 0.86.2
Version 0.86
Version 0.86 rc1
Version 0.87.1
Version 0.87
Version 0.88.1
Version 0.88.2
Version 0.88.3
Version 0.88.4
Version 0.88.5
Version 0.88.6
Version 0.88.7
Version 0.88
Version 0.90.1
Version 0.90.2
Version 0.90.3
Version 0.90
Version 0.90 rc1.1
Version 0.90 rc1
Version 0.90 rc2
Version 0.90 rc3
Version 0.91.1
Version 0.91.2
Version 0.91
Version 0.91 rc1
Version 0.91 rc2
Version 0.92.1
Version 0.92
Version 0.93.1
Version 0.93.2
Version 0.93.3
Version 0.93
Version 0.94.1
Version 0.94.2
Version 0.94
Version 0.95.1
Version 0.95.2
Version 0.95.3
Version 0.95
Version 0.95 rc1
Version 0.95 rc2
Version 0.96 rc1
Version 0.9 rc1
Clamavs
Version 0.04
Version 0.06

References (32)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.