PT-2017-3504 · Cisco+3 · Clamav+3
Publicado
2017-10-26
·
Atualizado
2026-02-06
·
CVE-2017-12377
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ClamAV versions 0.99.2 and prior
Description
The issue is caused by a buffer over-read condition in the
mew.c file when scanning a malicious file, potentially allowing a remote attacker to cause a denial of service condition or execute arbitrary code on an affected device. The vulnerability is due to improper input validation checking mechanisms in mew packet files sent to an affected device.Recommendations
For ClamAV versions 0.99.2 and prior, update to a version that contains a fix for this issue to prevent potential exploitation. As a temporary workaround, consider restricting the use of the
lzma bswap 4861dc function in mew.c until a patch is available.Exploit
Correção
DoS
Out of bounds Read
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Clamav
Suse
Ubuntu