Loading
Generated remediation guidance and an executive summary. No account required.
Integer signedness error in the (1) cab_unstore and (2) cab_extract functions in libclamav/cab.c in Clam AntiVirus (ClamAV) before 0.90.2 allow remote attackers to execute arbitrary code via a crafted CHM file that contains a negative integer, which passes a signed comparison and leads to a stack-based buffer overflow.
Use Clam Anti-Virus vendor hub and Clamav product page to widen CVE-2007-1997 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2008-1100, CVE-2008-5050 and CVE-2008-1833 for nearby disclosures in the same product family.