CVE-2008-3914
UnknownEPSS 3.58%
Last modified
CVE-2008-3914 is a vulnerability of currently unknown severity. Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the "error path" in (1) libclamav/others.c and (2) libclamav/sis.c.. EPSS estimates a 3.58% chance of exploitation in the next 30 days.
Description
Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the "error path" in (1) libclamav/others.c and (2) libclamav/sis.c.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Clamav | Clamav | <= 0.93.3 |
References
- http://kolab.org/security/kolab-vendor-notice-22.txtThird Party Advisory
- http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/31906Third Party Advisory
- http://secunia.com/advisories/31982Third Party Advisory
- http://secunia.com/advisories/32030Third Party Advisory
- http://secunia.com/advisories/32222Third Party Advisory
- http://secunia.com/advisories/32424Third Party Advisory
- http://secunia.com/advisories/32699Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200809-18.xmlThird Party Advisory
- http://sourceforge.net/project/shownotes.php?group_id=86638&release_id=623661Patch, Third Party Advisory
- http://support.apple.com/kb/HT3216Third Party Advisory
- http://svn.clamav.net/svn/clamav-devel/trunk/ChangeLogVendor Advisory
- http://www.debian.org/security/2008/dsa-1660Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:189Third Party Advisory
- http://www.openwall.com/lists/oss-security/2008/09/03/2Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/31051Patch, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/31681Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020828Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/2564Permissions Required
- http://www.vupen.com/english/advisories/2008/2780Permissions Required
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45058Third Party Advisory, VDB Entry
- https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1141Issue Tracking
- http://kolab.org/security/kolab-vendor-notice-22.txtThird Party Advisory
- http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/31906Third Party Advisory
- http://secunia.com/advisories/31982Third Party Advisory
- http://secunia.com/advisories/32030Third Party Advisory
- http://secunia.com/advisories/32222Third Party Advisory
- http://secunia.com/advisories/32424Third Party Advisory
- http://secunia.com/advisories/32699Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200809-18.xmlThird Party Advisory
- http://sourceforge.net/project/shownotes.php?group_id=86638&release_id=623661Patch, Third Party Advisory
- http://support.apple.com/kb/HT3216Third Party Advisory
- http://svn.clamav.net/svn/clamav-devel/trunk/ChangeLogVendor Advisory
- http://www.debian.org/security/2008/dsa-1660Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:189Third Party Advisory
- http://www.openwall.com/lists/oss-security/2008/09/03/2Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/31051Patch, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/31681Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020828Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/2564Permissions Required
- http://www.vupen.com/english/advisories/2008/2780Permissions Required
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45058Third Party Advisory, VDB Entry
- https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1141Issue Tracking
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-3914?
Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the "error path" in (1) libclamav/others.c and (2) libclamav/sis.c.
How severe is CVE-2008-3914?
Severity scoring for CVE-2008-3914 is pending analysis. The EPSS model estimates a 3.58% probability of exploitation in the next 30 days.
How do I fix CVE-2008-3914?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-3908Multiple buffer overflows in Princeton WordNet (wn) 3.0 allo…
- CVE-2008-3909The administration application in Django 0.91, 0.95, and 0.9…
- CVE-2008-3910dns2tcp before 0.4.1 does not properly handle negative value…
- CVE-2008-3911The proc_do_xprt function in net/sunrpc/sysctl.c in the Linu…
- CVE-2008-3912libclamav in ClamAV before 0.94 allows attackers to cause a …
- CVE-2008-3913Multiple memory leaks in freshclam/manager.c in ClamAV befor…
- CVE-2008-3915Buffer overflow in nfsd in the Linux kernel before 2.6.26.4,…
- CVE-2008-3916Heap-based buffer overflow in the strip_escapes function in …
- CVE-2008-3917Cross-site scripting (XSS) vulnerability in index.php in Ovi…
- CVE-2008-3918SQL injection vulnerability in index.php in Ovidentia 6.6.5 …
- CVE-2008-3919Unspecified vulnerability in multiple JustSystems Ichitaro p…
- CVE-2008-3920Unspecified vulnerability in BitlBee before 1.2.2 allows rem…
Are you affected by CVE-2008-3914?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
