CVE-2010-0098 describes a critical vulnerability in ClamAV versions prior to 0.96, affecting its ability to properly scan CAB and 7z archive files. This flaw allows remote attackers to bypass virus detection by crafting malicious archives that appear legitimate to standard archive utilities. With a CVSS score of 10.0, this vulnerability poses a severe risk to confidentiality, integrity, and availability, requiring no authentication or complex attack methods. Despite its high severity, there is no evidence of active exploitation, public exploit code, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.96CPE matchmatch criteria | cpe:2.3:a:clamav:clamav:*:rc2:*:*:*:*:*:* | ||
0.01CPE matchmatch criteria | cpe:2.3:a:clamav:clamav:0.01:*:*:*:*:*:*:* | ||
0.02CPE matchmatch criteria | cpe:2.3:a:clamav:clamav:0.02:*:*:*:*:*:*:* | ||
0.3CPE matchmatch criteria | cpe:2.3:a:clamav:clamav:0.3:*:*:*:*:*:*:* | ||
0.03CPE matchmatch criteria | cpe:2.3:a:clamav:clamav:0.03:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.