CVE-2018-0202
published 2018-03-27CVE-2018-0202: clamscan in ClamAV before 0.99.4 contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on…
PriorityP426medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
2.67%
84.2th percentile
clamscan in ClamAV before 0.99.4 contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation checking mechanisms when handling Portable Document Format (.pdf) files sent to an affected device. An unauthenticated, remote attacker could exploit this vulnerability by sending a crafted .pdf file to an affected device. This action could cause an out-of-bounds read when ClamAV scans the malicious file, allowing the attacker to cause a DoS condition. This concerns pdf_parse_array and pdf_parse_string in libclamav/pdfng.c. Cisco Bug IDs: CSCvh91380, CSCvh91400.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| clamav | clamav | <= 0.99.3 | — |
| clamav | clamav | — | — |
| clamav | clamav | >= 0 < 0.100.0~beta+dfsg-2 | 0.100.0~beta+dfsg-2 |
| clamav | clamav | >= 0 < 0.100.0~beta+dfsg-2 | 0.100.0~beta+dfsg-2 |
| clamav | clamav | >= 0 < 0.100.0~beta+dfsg-2 | 0.100.0~beta+dfsg-2 |
| clamav | clamav | >= 0 < 0.100.0~beta+dfsg-2 | 0.100.0~beta+dfsg-2 |
| clamav | clamav | >= 0 < 0.99.4+addedllvm-0ubuntu0.14.04.1 | 0.99.4+addedllvm-0ubuntu0.14.04.1 |
| clamav | clamav | >= 0 < 0.99.4+addedllvm-0ubuntu0.16.04.1 | 0.99.4+addedllvm-0ubuntu0.16.04.1 |
| debian | clamav | < clamav 0.100.0~beta+dfsg-2 (bookworm) | clamav 0.100.0~beta+dfsg-2 (bookworm) |
| debian | debian_linux | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
ClamAV vulnerabilities
vendor_ubuntu·2018-03-08·CVSS 5.5
CVE-2018-0202 [MEDIUM] ClamAV vulnerabilities
Title: ClamAV vulnerabilities
Summary: Several security issues were fixed in ClamAV.
USN-3592-1 fixed several vulnerabilities in ClamAV. This update
provides the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that ClamAV incorrectly handled parsing certain PDF
files. A remote attacker could use this issue to cause ClamAV to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2018-0202)
Hanno Böck discovered that ClamAV incorrectly handled parsing certain XAR
files. A remote attacker could use this issue to cause ClamAV to crash,
resulting in a denial of service. (CVE-2018-1000085)
Instructions: This update uses a new upstream release, which includes additional bug fixes. In general, a standard system update will m
Ubuntu
ClamAV vulnerabilities
vendor_ubuntu·2018-03-08·CVSS 5.5
CVE-2018-0202 [MEDIUM] ClamAV vulnerabilities
Title: ClamAV vulnerabilities
Summary: Several security issues were fixed in ClamAV.
It was discovered that ClamAV incorrectly handled parsing certain PDF
files. A remote attacker could use this issue to cause ClamAV to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2018-0202)
Hanno Böck discovered that ClamAV incorrectly handled parsing certain XAR
files. A remote attacker could use this issue to cause ClamAV to crash,
resulting in a denial of service. (CVE-2018-1000085)
Instructions: This update uses a new upstream release, which includes additional bug fixes. In general, a standard system update will make all the necessary changes.
Debian
CVE-2018-0202: clamav - clamscan in ClamAV before 0.99.4 contains a vulnerability that could allow an un...
vendor_debian·2018·CVSS 5.5
CVE-2018-0202 [MEDIUM] CVE-2018-0202: clamav - clamscan in ClamAV before 0.99.4 contains a vulnerability that could allow an un...
clamscan in ClamAV before 0.99.4 contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation checking mechanisms when handling Portable Document Format (.pdf) files sent to an affected device. An unauthenticated, remote attacker could exploit this vulnerability by sending a crafted .pdf file to an affected device. This action could cause an out-of-bounds read when ClamAV scans the malicious file, allowing the attacker to cause a DoS condition. This concerns pdf_parse_array and pdf_parse_string in libclamav/pdfng.c. Cisco Bug IDs: CSCvh91380, CSCvh91400.
Scope: local
bookworm: resolved (fixed in 0.100.0~beta+dfsg-2)
bullseye: resolved (fixed in 0.100.0~
GHSA
GHSA-r382-prm5-5rqf: clamscan in ClamAV before 0
ghsa_unreviewed·2022-05-14
CVE-2018-0202 [MEDIUM] CWE-125 GHSA-r382-prm5-5rqf: clamscan in ClamAV before 0
clamscan in ClamAV before 0.99.4 contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation checking mechanisms when handling Portable Document Format (.pdf) files sent to an affected device. An unauthenticated, remote attacker could exploit this vulnerability by sending a crafted .pdf file to an affected device. This action could cause an out-of-bounds read when ClamAV scans the malicious file, allowing the attacker to cause a DoS condition. This concerns pdf_parse_array and pdf_parse_string in libclamav/pdfng.c. Cisco Bug IDs: CSCvh91380, CSCvh91400.
OSV
CVE-2018-0202: clamscan in ClamAV before 0
osv·2018-03-27·CVSS 5.5
CVE-2018-0202 [MEDIUM] CVE-2018-0202: clamscan in ClamAV before 0
clamscan in ClamAV before 0.99.4 contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation checking mechanisms when handling Portable Document Format (.pdf) files sent to an affected device. An unauthenticated, remote attacker could exploit this vulnerability by sending a crafted .pdf file to an affected device. This action could cause an out-of-bounds read when ClamAV scans the malicious file, allowing the attacker to cause a DoS condition. This concerns pdf_parse_array and pdf_parse_string in libclamav/pdfng.c. Cisco Bug IDs: CSCvh91380, CSCvh91400.
OSV
clamav vulnerabilities
osv·2018-03-08·CVSS 5.5
CVE-2018-0202 [MEDIUM] clamav vulnerabilities
clamav vulnerabilities
It was discovered that ClamAV incorrectly handled parsing certain PDF
files. A remote attacker could use this issue to cause ClamAV to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2018-0202)
Hanno Böck discovered that ClamAV incorrectly handled parsing certain XAR
files. A remote attacker could use this issue to cause ClamAV to crash,
resulting in a denial of service. (CVE-2018-1000085)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.clamav.net/show_bug.cgi?id=11973https://bugzilla.clamav.net/show_bug.cgi?id=11980https://lists.debian.org/debian-lts-announce/2018/03/msg00011.htmlhttps://security.gentoo.org/glsa/201804-16https://usn.ubuntu.com/3592-1/https://usn.ubuntu.com/3592-2/https://bugzilla.clamav.net/show_bug.cgi?id=11973https://bugzilla.clamav.net/show_bug.cgi?id=11980https://lists.debian.org/debian-lts-announce/2018/03/msg00011.htmlhttps://security.gentoo.org/glsa/201804-16https://usn.ubuntu.com/3592-1/https://usn.ubuntu.com/3592-2/
2018-03-27
Published