PT-2017-3504 · Cisco+3 · Clamav+3

Publicado

2017-10-26

·

Atualizado

2026-02-06

·

CVE-2017-12377

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ClamAV versions 0.99.2 and prior
Description The issue is caused by a buffer over-read condition in the mew.c file when scanning a malicious file, potentially allowing a remote attacker to cause a denial of service condition or execute arbitrary code on an affected device. The vulnerability is due to improper input validation checking mechanisms in mew packet files sent to an affected device.
Recommendations For ClamAV versions 0.99.2 and prior, update to a version that contains a fix for this issue to prevent potential exploitation. As a temporary workaround, consider restricting the use of the lzma bswap 4861dc function in mew.c until a patch is available.

Exploit

Correção

DoS

Out of bounds Read

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-1096
BDU:2018-00338
CLEANSTART-2026-LA13761
CLEANSTART-2026-NJ87139
CLEANSTART-2026-TC95380
CLEANSTART-2026-WX01708
CVE-2017-12377
DLA-1261-1
MGASA-2018-0117
OPENSUSE-SU-2018_0258-1
OPENSUSE-SU-2024:10685-1
SUSE-SU-2018:0254-1
SUSE-SU-2018:0255-1
USN-3550-1
USN-3550-2

Produtos afetados

Alt Linux
Clamav
Suse
Ubuntu