Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-2650

16
FAUCET Score

CVE-2007-2650 describes a denial-of-service vulnerability in the OLE2 parser of Clam AntiVirus (ClamAV), affecting various distributions including Debian. This flaw allows remote attackers to exhaust system resources or trigger an infinite loop by submitting a specially crafted OLE2 file, such as a DOC file, containing either an excessively large property size or a loop in the FAT file block chain. The vulnerability has a CVSS score of 4.3 (Medium), indicating a network-based attack with medium complexity and partial availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.90.3CPE matchmatch criteria
cpe:2.3:a:clamav:clamav:*:*:*:*:*:*:*:*
3.1CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*
4.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.3MEDIUM

AV:N/AC:M/Au:N/C:N/I:N/A:P

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
3.25%
Probability of exploitation in next 30 days
EPSS Percentile
87.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0325 is in the 81st percentile among its peer group of 19,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

microsoftpatch availablevia msrc
Product: clamav-0.103.2-1.cm1.x86_64.rpm on CBL Mariner 1.0 x64Fixed in: 0.103.2-1
microsoftpatch availablevia msrc
Product: clamav-debuginfo-0.103.2-1.cm1.x86_64.rpm on CBL Mariner 1.0 x64Fixed in: 0.103.2-1
microsoftpatch availablevia msrc
Product: clamav-0.103.2-1.cm1.aarch64.rpm on CBL Mariner 1.0 ARMFixed in: 0.103.2-1
microsoftpatch availablevia msrc
Product: clamav-debuginfo-0.103.2-1.cm1.aarch64.rpm on CBL Mariner 1.0 ARMFixed in: 0.103.2-1
microsoftpatch availablevia msrc
Product: 13841-12137Fixed in: 0.103.2-1
microsoftpatch availablevia msrc
Product: 13842-12137Fixed in: 0.103.2-1
microsoftpatch availablevia msrc
Product: 13843-12138Fixed in: 0.103.2-1
microsoftpatch availablevia msrc
Product: 13844-12138Fixed in: 0.103.2-1
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 0.103.2-1
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 0.103.2-1

Vendor Advisories (2)

microsoft2020-Oct/CVE-2007-2650

CVE-2007-2650

Oct 13, 2020
microsoft2007-May/CVE-2007-2650

The OLE2 parser in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service (resource consumption) via an OLE2 file with (1) a large property size or (2) a loop in the FAT file block chain that triggers an infinite loop as demonstrated via a crafted DOC file.

May 2, 2007

References

article.gmane.org / gmane.comp.security.virus.clamav.devel/2853
Broken Link
kolab.org / security/kolab-vendor-notice-15.txt
Broken Link
lurker.clamav.net / message/20070418.111144.0df6c5d3.en.html
Broken Link
secunia.com / advisories/25244
PatchThird Party Advisory
secunia.com / advisories/25523
Third Party Advisory
secunia.com / advisories/25525
Third Party Advisory
secunia.com / advisories/25553
Third Party Advisory
secunia.com / advisories/25558
Third Party Advisory
secunia.com / advisories/25688
Third Party Advisory
secunia.com / advisories/25796
Third Party Advisory
security.gentoo.org / glsa/glsa-200706-05.xml
Third Party Advisory
svn.clamav.net / svn/clamav-devel/trunk/ChangeLog
Broken Link
debian.org / security/2007/dsa-1320
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
novell.com / linux/security/advisories/2007_33_clamav.html
Third Party Advisory
securityfocus.com / bid/24316
Third Party AdvisoryVDB Entry
trustix.org / errata/2007/0020
Broken Link
vupen.com / english/advisories/2007/1776
Permissions Required