CVE-2018-0361
published 2018-07-16CVE-2018-0361: ClamAV before 0.100.1 lacks a PDF object length check, resulting in an unreasonably long time to parse a relatively small file.
PriorityP49low3.3CVSS 3.0
AVLACLPRNUIRSUCNINAL
EPSS
1.62%
73.6th percentile
ClamAV before 0.100.1 lacks a PDF object length check, resulting in an unreasonably long time to parse a relatively small file.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| clamav | clamav | < 0.100.1 | 0.100.1 |
| clamav | clamav | >= 0 < 0.100.1+dfsg-1 | 0.100.1+dfsg-1 |
| clamav | clamav | >= 0 < 0.100.1+dfsg-1 | 0.100.1+dfsg-1 |
| clamav | clamav | >= 0 < 0.100.1+dfsg-1 | 0.100.1+dfsg-1 |
| clamav | clamav | >= 0 < 0.100.1+dfsg-1 | 0.100.1+dfsg-1 |
| clamav | clamav | >= 0 < 0.100.1+dfsg-1ubuntu0.14.04.4 | 0.100.1+dfsg-1ubuntu0.14.04.4 |
| clamav | clamav | >= 0 < 0.100.1+dfsg-1ubuntu0.14.04.1 | 0.100.1+dfsg-1ubuntu0.14.04.1 |
| clamav | clamav | >= 0 < 0.100.1+dfsg-1ubuntu0.14.04.2 | 0.100.1+dfsg-1ubuntu0.14.04.2 |
| clamav | clamav | >= 0 < 0.100.1+dfsg-1ubuntu0.16.04.3 | 0.100.1+dfsg-1ubuntu0.16.04.3 |
| clamav | clamav | >= 0 < 0.100.1+dfsg-1ubuntu0.16.04.1 | 0.100.1+dfsg-1ubuntu0.16.04.1 |
| clamav | clamav | >= 0 < 0.100.1+dfsg-1ubuntu0.16.04.2 | 0.100.1+dfsg-1ubuntu0.16.04.2 |
| clamav | clamav | >= 0 < 0.100.1+dfsg-1ubuntu0.18.04.3 | 0.100.1+dfsg-1ubuntu0.18.04.3 |
| clamav | clamav | >= 0 < 0.100.1+dfsg-1ubuntu0.18.04.1 | 0.100.1+dfsg-1ubuntu0.18.04.1 |
| clamav | clamav | >= 0 < 0.100.1+dfsg-1ubuntu0.18.04.2 | 0.100.1+dfsg-1ubuntu0.18.04.2 |
| debian | clamav | < clamav 0.100.1+dfsg-1 (bookworm) | clamav 0.100.1+dfsg-1 (bookworm) |
| debian | debian_linux | — | — |
CVSS provenance
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_ubuntu5.5MEDIUM
vendor_debian3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6v8f-c4v7-qcfg: ClamAV before 0
ghsa_unreviewed·2022-05-14
CVE-2018-0361 [MEDIUM] CWE-20 GHSA-6v8f-c4v7-qcfg: ClamAV before 0
ClamAV before 0.100.1 lacks a PDF object length check, resulting in an unreasonably long time to parse a relatively small file.
OSV
clamav regression
osv·2018-09-18·CVSS 5.5
CVE-2018-0360 [MEDIUM] clamav regression
clamav regression
USN-3722-1 fixed vulnerabilities in ClamAV. The new package introduced an
issue which caused dpkg-reconfigure to enter an infinite loop. This update
fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that ClamAV incorrectly handled parsing certain HWP
files. A remote attacker could use this issue to cause ClamAV to hang,
resulting in a denial of service. (CVE-2018-0360)
It was discovered that ClamAV incorrectly handled parsing certain PDF
files. A remote attacker could use this issue to cause ClamAV to hang,
resulting in a denial of service. (CVE-2018-0361)
OSV
clamav regression
osv·2018-07-26·CVSS 5.5
[MEDIUM] clamav regression
clamav regression
USN-3722-1 fixed vulnerabilities in ClamAV. The updated ClamAV version
removed some configuration options which caused the daemon to fail to start
in environments where the ClamAV configuration file was manually edited.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that ClamAV incorrectly handled parsing certain HWP
files. A remote attacker could use this issue to cause ClamAV to hang,
resulting in a denial of service. (CVE-2018-0360)
It was discovered that ClamAV incorrectly handled parsing certain PDF
files. A remote attacker could use this issue to cause ClamAV to hang,
resulting in a denial of service. (CVE-2018-0361)
OSV
clamav vulnerabilities
osv·2018-07-24·CVSS 5.5
CVE-2018-0360 [MEDIUM] clamav vulnerabilities
clamav vulnerabilities
It was discovered that ClamAV incorrectly handled parsing certain HWP
files. A remote attacker could use this issue to cause ClamAV to hang,
resulting in a denial of service. (CVE-2018-0360)
It was discovered that ClamAV incorrectly handled parsing certain PDF
files. A remote attacker could use this issue to cause ClamAV to hang,
resulting in a denial of service. (CVE-2018-0361)
OSV
CVE-2018-0361: ClamAV before 0
osv·2018-07-16·CVSS 3.3
CVE-2018-0361 [LOW] CVE-2018-0361: ClamAV before 0
ClamAV before 0.100.1 lacks a PDF object length check, resulting in an unreasonably long time to parse a relatively small file.
Ubuntu
ClamAV vulnerabilities
vendor_ubuntu·2018-09-18·CVSS 5.5
[MEDIUM] ClamAV vulnerabilities
Title: ClamAV vulnerabilities
Summary: USN-3722-1 introduced a regression in ClamAV.
USN-3722-1 fixed vulnerabilities in ClamAV. The new package introduced an
issue which caused dpkg-reconfigure to enter an infinite loop. This update
fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that ClamAV incorrectly handled parsing certain HWP
files. A remote attacker could use this issue to cause ClamAV to hang,
resulting in a denial of service. (CVE-2018-0360)
It was discovered that ClamAV incorrectly handled parsing certain PDF
files. A remote attacker could use this issue to cause ClamAV to hang,
resulting in a denial of service. (CVE-2018-0361)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
ClamAV regression
vendor_ubuntu·2018-09-18·CVSS 5.5
[MEDIUM] ClamAV regression
Title: ClamAV regression
Summary: USN-3722-1 introduced a regression in ClamAV.
USN-3722-1 fixed vulnerabilities in ClamAV. The new package introduced an
issue which caused dpkg-reconfigure to enter an infinite loop. This update
fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that ClamAV incorrectly handled parsing certain HWP
files. A remote attacker could use this issue to cause ClamAV to hang,
resulting in a denial of service. (CVE-2018-0360)
It was discovered that ClamAV incorrectly handled parsing certain PDF
files. A remote attacker could use this issue to cause ClamAV to hang,
resulting in a denial of service. (CVE-2018-0361)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
ClamAV regression
vendor_ubuntu·2018-07-26·CVSS 5.5
[MEDIUM] ClamAV regression
Title: ClamAV regression
Summary: USN-3722-1 introduced a regression in ClamAV.
USN-3722-1 fixed vulnerabilities in ClamAV. The updated ClamAV version
removed some configuration options which caused the daemon to fail to start
in environments where the ClamAV configuration file was manually edited.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that ClamAV incorrectly handled parsing certain HWP
files. A remote attacker could use this issue to cause ClamAV to hang,
resulting in a denial of service. (CVE-2018-0360)
It was discovered that ClamAV incorrectly handled parsing certain PDF
files. A remote attacker could use this issue to cause ClamAV to hang,
resulting in a denial of service. (CVE-2018-0361)
Instructions: In
Ubuntu
ClamAV vulnerabilities
vendor_ubuntu·2018-07-25·CVSS 5.5
CVE-2018-0360 [MEDIUM] ClamAV vulnerabilities
Title: ClamAV vulnerabilities
Summary: ClamAV could be made to hang if it opened a specially crafted file.
USN-3722-1 fixed a vulnerability in ClamAV. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that ClamAV incorrectly handled parsing certain HWP
files. A remote attacker could use this issue to cause ClamAV to hang,
resulting in a denial of service. (CVE-2018-0360)
It was discovered that ClamAV incorrectly handled parsing certain PDF
files. A remote attacker could use this issue to cause ClamAV to hang,
resulting in a denial of service. (CVE-2018-0361)
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
Ubuntu
ClamAV vulnerabilities
vendor_ubuntu·2018-07-24·CVSS 5.5
CVE-2018-0360 [MEDIUM] ClamAV vulnerabilities
Title: ClamAV vulnerabilities
Summary: ClamAV could be made to hang if it opened a specially crafted file.
It was discovered that ClamAV incorrectly handled parsing certain HWP
files. A remote attacker could use this issue to cause ClamAV to hang,
resulting in a denial of service. (CVE-2018-0360)
It was discovered that ClamAV incorrectly handled parsing certain PDF
files. A remote attacker could use this issue to cause ClamAV to hang,
resulting in a denial of service. (CVE-2018-0361)
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
Debian
CVE-2018-0361: clamav - ClamAV before 0.100.1 lacks a PDF object length check, resulting in an unreasona...
vendor_debian·2018·CVSS 3.3
CVE-2018-0361 [LOW] CVE-2018-0361: clamav - ClamAV before 0.100.1 lacks a PDF object length check, resulting in an unreasona...
ClamAV before 0.100.1 lacks a PDF object length check, resulting in an unreasonably long time to parse a relatively small file.
Scope: local
bookworm: resolved (fixed in 0.100.1+dfsg-1)
bullseye: resolved (fixed in 0.100.1+dfsg-1)
forky: resolved (fixed in 0.100.1+dfsg-1)
sid: resolved (fixed in 0.100.1+dfsg-1)
trixie: resolved (fixed in 0.100.1+dfsg-1)
No detection rules found.
No public exploits indexed.
http://www.securitytracker.com/id/1041367https://blog.clamav.net/2018/07/clamav-01001-has-been-released.htmlhttps://lists.debian.org/debian-lts-announce/2018/08/msg00020.htmlhttps://security.gentoo.org/glsa/201904-12http://www.securitytracker.com/id/1041367https://blog.clamav.net/2018/07/clamav-01001-has-been-released.htmlhttps://lists.debian.org/debian-lts-announce/2018/08/msg00020.htmlhttps://security.gentoo.org/glsa/201904-12
2018-07-16
Published