Integer overflow in ClamAV 0.88.1 and 0.88.4, and other versions before 0.88.5, allows remote attackers to cause a denial of service (scanning service crash) and execute arbitrary code via a crafted Portable Executable (PE) file that leads to a heap-based buffer overflow when less memory is allocated than expected.
No PoCs from references.
- https://github.com/ARPSyndicate/cve-scores
- https://github.com/mudongliang/LinuxFlaw
- https://github.com/oneoy/cve-