CVE-2017-12377Out-of-bounds Read in Clamav

CWE-125Out-of-bounds Read10 documents6 sources
Severity
9.8CRITICALNVD
OSV7.5
EPSS
21.4%
top 4.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 26
Latest updateMay 13

Description

ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or potentially execute arbitrary code on an affected device. The vulnerability is due to improper input validation checking mechanisms in mew packet files sent to an affected device. A successful exploit could cause a heap-based buffer over-read condition in mew.c when ClamAV scans the malicious file, allowing the attacker t

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

debiandebian/clamav< clamav 0.99.3~beta2+dfsg-1 (bookworm)
Debianclamav/clamav< 0.99.3~beta2+dfsg-1+3
Ubuntuclamav/clamav< 0.99.3+addedllvm-0ubuntu0.14.04.1+1
NVDclamav/clamav0.99.2

Also affects: Debian Linux 7.0

🔴Vulnerability Details

3
GHSA
GHSA-7jpj-m78q-vr62: ClamAV AntiVirus software versions 02022-05-13
OSV
clamav vulnerabilities2018-01-30
OSV
CVE-2017-12377: ClamAV AntiVirus software versions 02018-01-26

📋Vendor Advisories

3
Ubuntu
ClamAV vulnerabilities2018-02-05
Ubuntu
ClamAV vulnerabilities2018-01-30
Debian
CVE-2017-12377: clamav - ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that...2017

💬Community

3
Bugzilla
CVE-2017-12374 CVE-2017-12375 CVE-2017-12376 CVE-2017-12377 CVE-2017-12378 CVE-2017-12379 CVE-2017-12380 clamav: Multiple vulnerabilities fixed in 0.99.3 [epel-all]2018-01-29
Bugzilla
CVE-2017-12374 CVE-2017-12375 CVE-2017-12376 CVE-2017-12377 CVE-2017-12378 CVE-2017-12379 CVE-2017-12380 clamav: Multiple vulnerabilities fixed in 0.99.32018-01-29
Bugzilla
CVE-2017-12374 CVE-2017-12375 CVE-2017-12376 CVE-2017-12377 CVE-2017-12378 CVE-2017-12379 CVE-2017-12380 clamav: Multiple vulnerabilities fixed in 0.99.3 [fedora-all]2018-01-29