CVE-2014-9050

medium
Published 2014-12-01 ยท Modified 2026-05-06
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
5.0

Description

Heap-based buffer overflow in the cli_scanpe function in libclamav/pe.c in ClamAV before 0.98.5 allows remote attackers to cause a denial of service (crash) via a crafted y0da Crypter PE file.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0.98.5+dfsg-1
debian debianbullseyefixed0.98.5+dfsg-1
debian debianforkyfixed0.98.5+dfsg-1
debian debiansidfixed0.98.5+dfsg-1
debian debiantrixiefixed0.98.5+dfsg-1

Application impact

VendorProductVersionsFixed
clamavclamav{"endIncluding":"0.94.3"}
clamavclamav0.01
clamavclamav0.02
clamavclamav0.3
clamavclamav0.03
clamavclamav0.05
clamavclamav0.8
clamavclamav0.9
clamavclamav0.10
clamavclamav0.12
clamavclamav0.13
clamavclamav0.14
clamavclamav0.15
clamavclamav0.20
clamavclamav0.21
clamavclamav0.22
clamavclamav0.23
clamavclamav0.24
clamavclamav0.51
clamavclamav0.52
clamavclamav0.53
clamavclamav0.54
clamavclamav0.60
clamavclamav0.60p
clamavclamav0.65
clamavclamav0.66
clamavclamav0.67
clamavclamav0.67-1
clamavclamav0.68
clamavclamav0.68.1
clamavclamav0.70
clamavclamav0.71
clamavclamav0.72
clamavclamav0.73
clamavclamav0.74
clamavclamav0.75
clamavclamav0.75.1
clamavclamav0.80
clamavclamav0.80_rc
clamavclamav0.81
clamavclamav0.82
clamavclamav0.83
clamavclamav0.84
clamavclamav0.85
clamavclamav0.85.1
clamavclamav0.86
clamavclamav0.86.1
clamavclamav0.86.2
clamavclamav0.87
clamavclamav0.87.1
clamavclamav0.88
clamavclamav0.88.1
clamavclamav0.88.2
clamavclamav0.88.3
clamavclamav0.88.4
clamavclamav0.88.5
clamavclamav0.88.6
clamavclamav0.88.7
clamavclamav0.88.7_p0
clamavclamav0.88.7_p1
clamavclamav0.90
clamavclamav0.90.1
clamavclamav0.90.1_p0
clamavclamav0.90.2
clamavclamav0.90.2_p0
clamavclamav0.90.3
clamavclamav0.90.3_p0
clamavclamav0.90.3_p1
clamavclamav0.91
clamavclamav0.91.1
clamavclamav0.91.2
clamavclamav0.91.2_p0
clamavclamav0.92
clamavclamav0.92.1
clamavclamav0.92_p0
clamavclamav0.93
clamavclamav0.93.1
clamavclamav0.93.2
clamavclamav0.93.3
clamavclamav0.94
clamavclamav0.94.1
clamavclamav0.94.2

References

CWEs

CWE-119

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.