PT-2018-5396 · Cisco+3 · Clamav+3

Published

2018-01-26

·

Updated

2026-02-06

·

CVE-2017-12380

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: ClamAV AntiVirus software versions 0.99.2 and prior
Description: The issue is caused by improper input validation checking mechanisms in the mbox.c file during certain mail parsing functions. An unauthenticated, remote attacker could exploit this by sending a crafted email, triggering a NULL pointer dereference condition when the email is scanned, potentially resulting in a denial of service (DoS) condition.
Recommendations: For ClamAV AntiVirus software versions 0.99.2 and prior, update to a version later than 0.99.2 to resolve the issue. As a temporary workaround, consider restricting the receipt of emails from untrusted sources to minimize the risk of exploitation.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1096
CLEANSTART-2026-LA13761
CLEANSTART-2026-NJ87139
CLEANSTART-2026-TC95380
CLEANSTART-2026-WX01708
CVE-2017-12380
DLA-1261-1
MGASA-2018-0117
OPENSUSE-SU-2018_0258-1
OPENSUSE-SU-2024:10685-1
SUSE-SU-2018:0254-1
SUSE-SU-2018:0255-1
USN-3550-1
USN-3550-2

Affected Products

Alt Linux
Clamav
Suse
Ubuntu