VYPR
Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026

CVE-2004-1909

CVE-2004-1909

Description

ClamAV 0.68 and earlier crashes when processing crafted RAR archives, causing denial of service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

ClamAV 0.68 and earlier crashes when processing crafted RAR archives, causing denial of service.

Vulnerability

ClamAV versions 0.68 and earlier are vulnerable to a denial of service crash when processing specially crafted RAR archives, such as those generated by variants of the W32.Beagle.A@mm worm. The crash occurs in the RAR parsing routine within the clamav process, triggered by malformed archive data. This issue affects all installations using versions prior to 0.68.1 [1].

Exploitation

An attacker can remotely exploit this vulnerability by sending a crafted RAR archive to a system running ClamAV. No authentication or user interaction is required; the crash occurs during automatic scanning, such as when the archive is received as an email attachment or accessed via a mail server integration. The specific archive structure that triggers the crash is characteristic of Beagle/Bagle worm variants, but any similar malformed RAR may cause the same effect [1].

Impact

Successful exploitation results in a denial of service (DoS) as the clamav process crashes. Depending on the system configuration, this can also cause dependent services, such as mail delivery or virus scanning daemons, to fail, disrupting normal operations. The crash does not lead to arbitrary code execution or data corruption, but the interruption of anti-virus services leaves systems temporarily unprotected [1].

Mitigation

The fixed version is ClamAV 0.68.1, released shortly after the vulnerability was disclosed. Users should upgrade to version >=0.68.1 immediately. No workaround exists for earlier versions, as the vulnerability is triggered by normal scanning activity. The Gentoo Linux GLSA 200404-07 provides upgrade instructions via emerge for Gentoo users [1]. There is no indication that this CVE is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3
  • ClamAV/Clamav3 versions
    cpe:2.3:a:clam_anti-virus:clamav:0.65:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:clam_anti-virus:clamav:0.65:*:*:*:*:*:*:*
    • cpe:2.3:a:clam_anti-virus:clamav:0.67:*:*:*:*:*:*:*
    • (no CPE)range: <=0.68

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.