CVE-2011-1003

Source
https://nvd.nist.gov/vuln/detail/CVE-2011-1003
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2011-1003.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2011-1003
Published
2011-02-23T19:00:02Z
Modified
2024-11-21T01:25:18Z
Summary
[none]
Details

Double free vulnerability in the vbareadprojectstrings function in vbaextract.c in libclamav in ClamAV before 0.97 might allow remote attackers to execute arbitrary code via crafted Visual Basic for Applications (VBA) data in a Microsoft Office document. NOTE: some of these details are obtained from third party information.

References

Affected packages

Debian:11 / clamav

Package

Name
clamav
Purl
pkg:deb/debian/clamav?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.97+dfsg-1

Ecosystem specific

{
    "urgency": "low"
}

Debian:12 / clamav

Package

Name
clamav
Purl
pkg:deb/debian/clamav?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.97+dfsg-1

Ecosystem specific

{
    "urgency": "low"
}

Debian:13 / clamav

Package

Name
clamav
Purl
pkg:deb/debian/clamav?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.97+dfsg-1

Ecosystem specific

{
    "urgency": "low"
}