CVE-2007-0898
EPSS 2.0%
Description
Directory traversal vulnerability in clamd in Clam AntiVirus ClamAV before 0.90 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the id MIME header parameter in a multi-part message.
How to fix CVE-2007-0898
To remediate CVE-2007-0898, upgrade the affected package to a fixed version below.
- Debian/clamav—upgrade to 0.90-1 or later
Is CVE-2007-0898 being exploited?
Low — EPSS is 2.0%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.90-1