CVE-2009-1241 describes an unspecified vulnerability in ClamAV versions prior to 0.95, allowing remote attackers to bypass malware detection. This vulnerability specifically impacts the scanning of modified RAR archives. With a CVSS score of 7.5, it is considered highly severe, indicating a network-based attack with low complexity and potential for partial compromise of confidentiality, integrity, and availability. Despite its severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.95CPE matchmatch criteria | cpe:2.3:a:clamav:clamav:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2009-1241
Oct 13, 2020Unspecified vulnerability in ClamAV before 0.95 allows remote attackers to bypass detection of malware via a modified RAR archive.
Apr 2, 2009clamav: security fixes in upstream 0.95 (CVE-2008-6680, CVE-2009-1270)