CVE-2004-1876

The "%f" feature in the VirusEvent directive in Clam AntiVirus daemon (clamd) before 0.70 allows local users to execute arbitrary commands via shell metacharacters in a file name.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:clam_anti-virus:clamav:0.51:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.52:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.53:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.54:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.60:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.65:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.67:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.68:*:*:*:*:*:*:*
cpe:2.3:a:clam_anti-virus:clamav:0.68.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2004-03-30 05:00

Updated : 2023-12-10 10:17


NVD link : CVE-2004-1876

Mitre link : CVE-2004-1876

CVE.ORG link : CVE-2004-1876


JSON object : View

Products Affected

clam_anti-virus

  • clamav