CVE-2016-1371
published 2016-10-03CVE-2016-1371: ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted mew packer executable.
PriorityP417medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
1.64%
74.0th percentile
ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted mew packer executable.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| clamav | clamav | <= 0.99.1 | — |
| clamav | clamav | >= 0 < 0.99.2+dfsg-1 | 0.99.2+dfsg-1 |
| clamav | clamav | >= 0 < 0.99.2+dfsg-1 | 0.99.2+dfsg-1 |
| clamav | clamav | >= 0 < 0.99.2+dfsg-1 | 0.99.2+dfsg-1 |
| clamav | clamav | >= 0 < 0.99.2+dfsg-1 | 0.99.2+dfsg-1 |
| debian | clamav | < clamav 0.99.2+dfsg-1 (bookworm) | clamav 0.99.2+dfsg-1 (bookworm) |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
ClamAV vulnerabilities
vendor_ubuntu·2016-09-28
CVE-2016-1371 ClamAV vulnerabilities
Title: ClamAV vulnerabilities
Summary: ClamAV could be made to crash or run programs if it processed a specially
crafted file.
It was discovered that ClamAV incorrectly handled certain malformed files.
A remote attacker could use this issue to cause ClamAV to crash, resulting
in a denial of service, or possibly execute arbitrary code.
In the default installation, attackers would be isolated by the ClamAV
AppArmor profile.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
Debian
CVE-2016-1371: clamav - ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a den...
vendor_debian·2016·CVSS 5.5
CVE-2016-1371 [MEDIUM] CVE-2016-1371: clamav - ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a den...
ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted mew packer executable.
Scope: local
bookworm: resolved (fixed in 0.99.2+dfsg-1)
bullseye: resolved (fixed in 0.99.2+dfsg-1)
forky: resolved (fixed in 0.99.2+dfsg-1)
sid: resolved (fixed in 0.99.2+dfsg-1)
trixie: resolved (fixed in 0.99.2+dfsg-1)
GHSA
Jenkins Credentials plugin reveals encrypted values of credentials to users with Extended Read permission
ghsa·2024-10-02
CVE-2024-47805 [MEDIUM] CWE-200 Jenkins Credentials plugin reveals encrypted values of credentials to users with Extended Read permission
Jenkins Credentials plugin reveals encrypted values of credentials to users with Extended Read permission
Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type (e.g., Certificate credentials, or Secret file credentials from Plain Credentials Plugin) when accessing item `config.xml` via REST API or CLI.
This allows attackers with Item/Extended Read permission to view encrypted `SecretBytes` values in credentials.
This issue is similar to SECURITY-266 in the 2016-05-11 security advisory, which applied to the `Secret` type used for inline secrets and some credentials types.
Credentials Plugin 1381.v2c3a_12074da_b_ redacts the encrypted values of credentials using the `Sec
GHSA
GHSA-x2x5-2j3g-8q37: ClamAV (aka Clam AntiVirus) before 0
ghsa_unreviewed·2022-05-17
CVE-2016-1371 [MEDIUM] CWE-284 GHSA-x2x5-2j3g-8q37: ClamAV (aka Clam AntiVirus) before 0
ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted mew packer executable.
OSV
CVE-2016-1371: ClamAV (aka Clam AntiVirus) before 0
osv·2016-10-03·CVSS 5.5
CVE-2016-1371 [MEDIUM] CVE-2016-1371: ClamAV (aka Clam AntiVirus) before 0
ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted mew packer executable.
No detection rules found.
No public exploits indexed.
http://blog.clamav.net/2016/05/clamav-0992-has-been-released.htmlhttp://www.securityfocus.com/bid/93222http://www.ubuntu.com/usn/USN-3093-1https://bugzilla.clamav.net/show_bug.cgi?id=11514https://foxglovesecurity.com/2016/06/13/finding-pearls-fuzzing-clamav/http://blog.clamav.net/2016/05/clamav-0992-has-been-released.htmlhttp://www.securityfocus.com/bid/93222http://www.ubuntu.com/usn/USN-3093-1https://bugzilla.clamav.net/show_bug.cgi?id=11514https://foxglovesecurity.com/2016/06/13/finding-pearls-fuzzing-clamav/
2016-10-03
Published