Vulnerability record · CVE-2007-4560 · published 28 August 2007
CVE-2007-4560: ClamAV clamav-milter black hole mode command injection
CClam Anti Virus · Clamav
clamav-milter in ClamAV before 0.91.2, when run in black hole mode, passes the sendmail recipient field into a popen call without sanitizing shell metacharacters. This allows OS command injection through crafted recipient data. The flaw matters because it turns a mail-handling component into a remote command execution vector.
Description
clamav-milter in ClamAV before 0.91.2, when run in black hole mode, allows remote attackers to execute arbitrary commands via shell metacharacters that are used in a certain popen call, involving the "recipient field of sendmail."
AV:N/AC:H/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote command execution with no authentication required, though high attack complexity and an available patch reduce urgency below critical.
What it is
clamav-milter in ClamAV before 0.91.2, when run in black hole mode, passes the sendmail recipient field into a popen call without sanitizing shell metacharacters. This allows OS command injection through crafted recipient data. The flaw matters because it turns a mail-handling component into a remote command execution vector.
Impact
An attacker can execute arbitrary commands with the privileges of the clamav-milter process. This can lead to full compromise of the mail gateway host.
Attack surface
Reached remotely over the network via sendmail recipient data processed by clamav-milter in black hole mode. No authentication is required per the CVSS vector (Au:N), though the attack is rated high complexity (AC:H).
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is very high (0.83539, 99.668th percentile), and references include Patch-tagged advisories, indicating public technical detail and fixes exist.
What to do
- Upgrade ClamAV to 0.91.2 or later, which fixes the popen command injection.
- If black hole mode is not required, disable it in clamav-milter configuration.
- Apply vendor security updates for ClamAV packages on affected distributions (Debian, Gentoo, Mandriva, Novell, Red Hat/Fedora, Trustix, Apple).
- Restrict network exposure of the milter/sendmail interface to trusted mail relays only.
- Run clamav-milter with least privilege so command execution does not yield root.
Detection
- Monitor clamav-milter and sendmail logs for unusual recipient strings containing shell metacharacters such as ;, |, $(), backticks, or newlines.
- Alert on child processes spawned by clamav-milter that are not expected scanner binaries.
- Audit mail gateway hosts for unexpected outbound connections or command execution following milter activity.
- Check for the presence of the vulnerable ClamAV version (<0.91.2) across mail infrastructure.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-4560 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-4560), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.