A vulnerability in the RAR file scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and 0.101.0 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a lack of proper error-handling mechanisms when processing nested RAR files sent to an affected device. An attacker could exploit this vulnerability by sending a crafted RAR file to an affected device. An exploit could allow the attacker to view or create arbitrary files on the targeted system.
{
"cpe": [
"cpe:2.3:a:clamav:clamav:0.101.0:*:*:*:*:*:*:*",
"cpe:2.3:a:clamav:clamav:0.101.1:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "0.101.0"
},
{
"last_affected": "0.101.1"
}
],
"source": "CPE_FIELD"
}