PT-2018-5396 · Cisco+3 · Clamav+3
Published
2018-01-26
·
Updated
2026-02-06
·
CVE-2017-12380
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
ClamAV AntiVirus software versions 0.99.2 and prior
Description:
The issue is caused by improper input validation checking mechanisms in the mbox.c file during certain mail parsing functions. An unauthenticated, remote attacker could exploit this by sending a crafted email, triggering a NULL pointer dereference condition when the email is scanned, potentially resulting in a denial of service (DoS) condition.
Recommendations:
For ClamAV AntiVirus software versions 0.99.2 and prior, update to a version later than 0.99.2 to resolve the issue. As a temporary workaround, consider restricting the receipt of emails from untrusted sources to minimize the risk of exploitation.
Exploit
Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Clamav
Suse
Ubuntu