CVE-2016-1405
published 2016-06-08CVE-2016-1405: libclamav in ClamAV (aka Clam AntiVirus), as used in Advanced Malware Protection (AMP) on Cisco Email Security Appliance (ESA) devices before 9.7.0-125 and Web…
PriorityP340high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
3.41%
87.6th percentile
libclamav in ClamAV (aka Clam AntiVirus), as used in Advanced Malware Protection (AMP) on Cisco Email Security Appliance (ESA) devices before 9.7.0-125 and Web Security Appliance (WSA) devices before 9.0.1-135 and 9.1.x before 9.1.1-041, allows remote attackers to cause a denial of service (AMP process restart) via a crafted document, aka Bug IDs CSCuv78533 and CSCuw60503.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | email_security_appliance | — | — |
| cisco | esa_and_wsa_amp_clamav | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
| clamav | clamav | >= 0 < 0.99+dfsg-1 | 0.99+dfsg-1 |
| clamav | clamav | >= 0 < 0.99+dfsg-1 | 0.99+dfsg-1 |
| clamav | clamav | >= 0 < 0.99+dfsg-1 | 0.99+dfsg-1 |
| clamav | clamav | >= 0 < 0.99+dfsg-1 | 0.99+dfsg-1 |
| debian | clamav | < clamav 0.99+dfsg-1 (bookworm) | clamav 0.99+dfsg-1 (bookworm) |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
ClamAV vulnerabilities
vendor_ubuntu·2016-09-28
CVE-2016-1371 ClamAV vulnerabilities
Title: ClamAV vulnerabilities
Summary: ClamAV could be made to crash or run programs if it processed a specially
crafted file.
It was discovered that ClamAV incorrectly handled certain malformed files.
A remote attacker could use this issue to cause ClamAV to crash, resulting
in a denial of service, or possibly execute arbitrary code.
In the default installation, attackers would be isolated by the ClamAV
AppArmor profile.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
Cisco
Cisco ESA and WSA AMP ClamAV Denial of Service Vulnerability
vendor_cisco·2016-05-31·CVSS 5.0
CVE-2016-1405 [MEDIUM] CWE-119 Cisco ESA and WSA AMP ClamAV Denial of Service Vulnerability
Cisco ESA and WSA AMP ClamAV Denial of Service Vulnerability
A vulnerability in the Clam AntiVirus (ClamAV) software that is used by Cisco Advance Malware Protection (AMP) for Cisco Email Security Appliances (ESAs) and Cisco Web Security Appliances (WSAs) could allow an unauthenticated, remote attacker to cause the AMP process to restart.
The vulnerability is due to improper parsing of input files by the libclamav library. An attacker could exploit this vulnerability by sending a crafted document that triggers a scan from the AMP ClamAV library on an affected system. A successful exploit could allow the attacker to cause the AMP process to restart.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisor
Debian
CVE-2016-1405: clamav - libclamav in ClamAV (aka Clam AntiVirus), as used in Advanced Malware Protection...
vendor_debian·2016·CVSS 7.5
CVE-2016-1405 [HIGH] CVE-2016-1405: clamav - libclamav in ClamAV (aka Clam AntiVirus), as used in Advanced Malware Protection...
libclamav in ClamAV (aka Clam AntiVirus), as used in Advanced Malware Protection (AMP) on Cisco Email Security Appliance (ESA) devices before 9.7.0-125 and Web Security Appliance (WSA) devices before 9.0.1-135 and 9.1.x before 9.1.1-041, allows remote attackers to cause a denial of service (AMP process restart) via a crafted document, aka Bug IDs CSCuv78533 and CSCuw60503.
Scope: local
bookworm: resolved (fixed in 0.99+dfsg-1)
bullseye: resolved (fixed in 0.99+dfsg-1)
forky: resolved (fixed in 0.99+dfsg-1)
sid: resolved (fixed in 0.99+dfsg-1)
trixie: resolved (fixed in 0.99+dfsg-1)
Cisco
Cisco ESA and WSA AMP ClamAV Denial of Service Vulnerability
vendor_cisco
CVE-2016-1405 Cisco ESA and WSA AMP ClamAV Denial of Service Vulnerability
CVE-2016-1405: Cisco ESA and WSA AMP ClamAV Denial of Service Vulnerability
A vulnerability in the Clam AntiVirus (ClamAV) software that is used by Cisco Advance Malware Protection (AMP) for Cisco Email Security Appliances (ESAs) and Cisco Web Security Appliances (WSAs) could allow an unauthenticated, remote attacker to cause the AMP process to restart. The vulnerability is due to improper parsing of input files by the libclamav library. An attacker could exploit this vulnerability by sending a crafted document that triggers a scan from the AMP ClamAV library on an affected system. A successful exploit could allow the attacker to cause the AMP process to restart. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-119, CWE-119
Bug IDs: CSCuv78533, CSC
GHSA
GHSA-p4qj-763m-ffg3: libclamav in ClamAV (aka Clam AntiVirus), as used in Advanced Malware Protection (AMP) on Cisco Email Security Appliance (ESA) devices before 9
ghsa_unreviewed·2022-05-17
CVE-2016-1405 [HIGH] CWE-119 GHSA-p4qj-763m-ffg3: libclamav in ClamAV (aka Clam AntiVirus), as used in Advanced Malware Protection (AMP) on Cisco Email Security Appliance (ESA) devices before 9
libclamav in ClamAV (aka Clam AntiVirus), as used in Advanced Malware Protection (AMP) on Cisco Email Security Appliance (ESA) devices before 9.7.0-125 and Web Security Appliance (WSA) devices before 9.0.1-135 and 9.1.x before 9.1.1-041, allows remote attackers to cause a denial of service (AMP process restart) via a crafted document, aka Bug IDs CSCuv78533 and CSCuw60503.
OSV
CVE-2016-1405: libclamav in ClamAV (aka Clam AntiVirus), as used in Advanced Malware Protection (AMP) on Cisco Email Security Appliance (ESA) devices before 9
osv·2016-06-08·CVSS 7.5
CVE-2016-1405 [HIGH] CVE-2016-1405: libclamav in ClamAV (aka Clam AntiVirus), as used in Advanced Malware Protection (AMP) on Cisco Email Security Appliance (ESA) devices before 9
libclamav in ClamAV (aka Clam AntiVirus), as used in Advanced Malware Protection (AMP) on Cisco Email Security Appliance (ESA) devices before 9.7.0-125 and Web Security Appliance (WSA) devices before 9.0.1-135 and 9.1.x before 9.1.1-041, allows remote attackers to cause a denial of service (AMP process restart) via a crafted document, aka Bug IDs CSCuv78533 and CSCuw60503.
No detection rules found.
No public exploits indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160531-wsa-esahttp://www.securityfocus.com/bid/90968http://www.securitytracker.com/id/1035993http://www.securitytracker.com/id/1035994http://www.ubuntu.com/usn/USN-3093-1https://github.com/vrtadmin/clamav-devel/blob/master/ChangeLoghttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160531-wsa-esahttp://www.securityfocus.com/bid/90968http://www.securitytracker.com/id/1035993http://www.securitytracker.com/id/1035994http://www.ubuntu.com/usn/USN-3093-1https://github.com/vrtadmin/clamav-devel/blob/master/ChangeLog
2016-06-08
Published