CVE-2007-2650 describes a denial-of-service vulnerability in the OLE2 parser of Clam AntiVirus (ClamAV), affecting various distributions including Debian. This flaw allows remote attackers to exhaust system resources or trigger an infinite loop by submitting a specially crafted OLE2 file, such as a DOC file, containing either an excessively large property size or a loop in the FAT file block chain. The vulnerability has a CVSS score of 4.3 (Medium), indicating a network-based attack with medium complexity and partial availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.90.3CPE matchmatch criteria | cpe:2.3:a:clamav:clamav:*:*:*:*:*:*:*:* | ||
3.1CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2007-2650
Oct 13, 2020The OLE2 parser in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service (resource consumption) via an OLE2 file with (1) a large property size or (2) a loop in the FAT file block chain that triggers an infinite loop as demonstrated via a crafted DOC file.
May 2, 2007