CVE-2015-1461
Description
ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted (1) Yoda's crypter or (2) mew packer file, related to a "heap out of bounds condition."
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
ClamAV before 0.98.6 has a heap out-of-bounds condition in Yoda's crypter and mew packer parsing, enabling remote attackers to cause unspecified impact via crafted files.
Vulnerability
A heap out-of-bounds condition exists in ClamAV versions before 0.98.6 when parsing crafted Yoda's crypter or mew packer files. This allows a remote attacker to trigger memory corruption via specially crafted files.
Exploitation
An attacker can send a crafted Yoda's crypter or mew packer file to a system running ClamAV scanning. No authentication is required; the file only needs to be scanned by ClamAV.
Impact
Successful exploitation can lead to unspecified impact, potentially including denial of service or arbitrary code execution.
Mitigation
Upgrade to ClamAV 0.98.6 or later, which includes fixes for these heap out-of-bounds conditions [1][4].
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
8cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*
- osv-coords4 versionspkg:rpm/opensuse/clamav&distro=openSUSE%20Tumbleweedpkg:rpm/suse/clamav&distro=SUSE%20Linux%20Enterprise%20Desktop%2012pkg:rpm/suse/clamav&distro=SUSE%20Linux%20Enterprise%20Server%2012pkg:rpm/suse/clamav&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012
< 0.99.2-4.1+ 3 more
- (no CPE)range: < 0.99.2-4.1
- (no CPE)range: < 0.98.6-10.1
- (no CPE)range: < 0.98.6-10.1
- (no CPE)range: < 0.98.6-10.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- blog.clamav.net/2015/01/clamav-0986-has-been-released.htmlnvdVendor Advisory
- lists.fedoraproject.org/pipermail/package-announce/2015-January/148950.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2015-January/148958.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2015-02/msg00014.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2015-02/msg00020.htmlnvd
- secunia.com/advisories/62536nvd
- securitytracker.com/id/1031672nvd
- security.gentoo.org/glsa/201512-08nvd
News mentions
0No linked articles in our index yet.