CVE-2018-1000085
published 2018-03-13CVE-2018-1000085: ClamAV version version 0.99.3 contains a Out of bounds heap memory read vulnerability in XAR parser, function xar_hash_check() that can result in Leaking of…
PriorityP421medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
1.64%
74.0th percentile
ClamAV version version 0.99.3 contains a Out of bounds heap memory read vulnerability in XAR parser, function xar_hash_check() that can result in Leaking of memory, may help in developing exploit chains.. This attack appear to be exploitable via The victim must scan a crafted XAR file. This vulnerability appears to have been fixed in after commit d96a6b8bcc7439fa7e3876207aa0a8e79c8451b6.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| clamav | clamav | — | — |
| clamav | clamav | >= 0 < 0.99.3~beta1+dfsg-1 | 0.99.3~beta1+dfsg-1 |
| clamav | clamav | >= 0 < 0.99.3~beta1+dfsg-1 | 0.99.3~beta1+dfsg-1 |
| clamav | clamav | >= 0 < 0.99.3~beta1+dfsg-1 | 0.99.3~beta1+dfsg-1 |
| clamav | clamav | >= 0 < 0.99.3~beta1+dfsg-1 | 0.99.3~beta1+dfsg-1 |
| clamav | clamav | >= 0 < 0.99.4+addedllvm-0ubuntu0.14.04.1 | 0.99.4+addedllvm-0ubuntu0.14.04.1 |
| clamav | clamav | >= 0 < 0.99.4+addedllvm-0ubuntu0.16.04.1 | 0.99.4+addedllvm-0ubuntu0.16.04.1 |
| debian | clamav | < clamav 0.99.3~beta1+dfsg-1 (bookworm) | clamav 0.99.3~beta1+dfsg-1 (bookworm) |
| debian | debian_linux | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
ClamAV vulnerabilities
vendor_ubuntu·2018-03-08·CVSS 5.5
CVE-2018-0202 [MEDIUM] ClamAV vulnerabilities
Title: ClamAV vulnerabilities
Summary: Several security issues were fixed in ClamAV.
USN-3592-1 fixed several vulnerabilities in ClamAV. This update
provides the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that ClamAV incorrectly handled parsing certain PDF
files. A remote attacker could use this issue to cause ClamAV to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2018-0202)
Hanno Böck discovered that ClamAV incorrectly handled parsing certain XAR
files. A remote attacker could use this issue to cause ClamAV to crash,
resulting in a denial of service. (CVE-2018-1000085)
Instructions: This update uses a new upstream release, which includes additional bug fixes. In general, a standard system update will m
Ubuntu
ClamAV vulnerabilities
vendor_ubuntu·2018-03-08·CVSS 5.5
CVE-2018-0202 [MEDIUM] ClamAV vulnerabilities
Title: ClamAV vulnerabilities
Summary: Several security issues were fixed in ClamAV.
It was discovered that ClamAV incorrectly handled parsing certain PDF
files. A remote attacker could use this issue to cause ClamAV to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2018-0202)
Hanno Böck discovered that ClamAV incorrectly handled parsing certain XAR
files. A remote attacker could use this issue to cause ClamAV to crash,
resulting in a denial of service. (CVE-2018-1000085)
Instructions: This update uses a new upstream release, which includes additional bug fixes. In general, a standard system update will make all the necessary changes.
Debian
CVE-2018-1000085: clamav - ClamAV version version 0.99.3 contains a Out of bounds heap memory read vulnerab...
vendor_debian·2018·CVSS 5.5
CVE-2018-1000085 [MEDIUM] CVE-2018-1000085: clamav - ClamAV version version 0.99.3 contains a Out of bounds heap memory read vulnerab...
ClamAV version version 0.99.3 contains a Out of bounds heap memory read vulnerability in XAR parser, function xar_hash_check() that can result in Leaking of memory, may help in developing exploit chains.. This attack appear to be exploitable via The victim must scan a crafted XAR file. This vulnerability appears to have been fixed in after commit d96a6b8bcc7439fa7e3876207aa0a8e79c8451b6.
Scope: local
bookworm: resolved (fixed in 0.99.3~beta1+dfsg-1)
bullseye: resolved (fixed in 0.99.3~beta1+dfsg-1)
forky: resolved (fixed in 0.99.3~beta1+dfsg-1)
sid: resolved (fixed in 0.99.3~beta1+dfsg-1)
trixie: resolved (fixed in 0.99.3~beta1+dfsg-1)
GHSA
GHSA-7p5r-r9rq-7w35: ClamAV version version 0
ghsa_unreviewed·2022-05-14
CVE-2018-1000085 [MEDIUM] CWE-125 GHSA-7p5r-r9rq-7w35: ClamAV version version 0
ClamAV version version 0.99.3 contains a Out of bounds heap memory read vulnerability in XAR parser, function xar_hash_check() that can result in Leaking of memory, may help in developing exploit chains.. This attack appear to be exploitable via The victim must scan a crafted XAR file. This vulnerability appears to have been fixed in after commit d96a6b8bcc7439fa7e3876207aa0a8e79c8451b6.
OSV
CVE-2018-1000085: ClamAV version version 0
osv·2018-03-13·CVSS 5.5
CVE-2018-1000085 [MEDIUM] CVE-2018-1000085: ClamAV version version 0
ClamAV version version 0.99.3 contains a Out of bounds heap memory read vulnerability in XAR parser, function xar_hash_check() that can result in Leaking of memory, may help in developing exploit chains.. This attack appear to be exploitable via The victim must scan a crafted XAR file. This vulnerability appears to have been fixed in after commit d96a6b8bcc7439fa7e3876207aa0a8e79c8451b6.
OSV
clamav vulnerabilities
osv·2018-03-08·CVSS 5.5
CVE-2018-0202 [MEDIUM] clamav vulnerabilities
clamav vulnerabilities
It was discovered that ClamAV incorrectly handled parsing certain PDF
files. A remote attacker could use this issue to cause ClamAV to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2018-0202)
Hanno Böck discovered that ClamAV incorrectly handled parsing certain XAR
files. A remote attacker could use this issue to cause ClamAV to crash,
resulting in a denial of service. (CVE-2018-1000085)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1000085 clamav: Out-of-bounds heap read in XAR parser [fedora-all]
bugzilla·2018-02-26·CVSS 5.5
CVE-2018-1000085 [MEDIUM] CVE-2018-1000085 clamav: Out-of-bounds heap read in XAR parser [fedora-all]
CVE-2018-1000085 clamav: Out-of-bounds heap read in XAR parser [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions o
Bugzilla
CVE-2018-1000085 clamav: Out-of-bounds heap read in XAR parser [epel-all]
bugzilla·2018-02-26·CVSS 5.5
CVE-2018-1000085 [MEDIUM] CVE-2018-1000085 clamav: Out-of-bounds heap read in XAR parser [epel-all]
CVE-2018-1000085 clamav: Out-of-bounds heap read in XAR parser [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fe
Bugzilla
CVE-2018-1000085 clamav: Out-of-bounds heap read in XAR parser
bugzilla·2018-02-26·CVSS 5.5
CVE-2018-1000085 [MEDIUM] CVE-2018-1000085 clamav: Out-of-bounds heap read in XAR parser
CVE-2018-1000085 clamav: Out-of-bounds heap read in XAR parser
An out-of-bounds heap read vulnerability was found in XAR parser that leads to clamscan crash when invoked on malicious XAR file.
Upstream patch:
https://github.com/Cisco-Talos/clamav-devel/commit/d96a6b8bcc7439fa7e3876207aa0a8e79c8451b6
Reference:
http://www.openwall.com/lists/oss-security/2017/09/29/4
Discussion:
Created clamav tracking bugs for this issue:
Affects: epel-all [bug 1549070]
Affects: fedora-all [bug 1549071]
http://www.openwall.com/lists/oss-security/2017/09/29/4https://github.com/Cisco-Talos/clamav-devel/commit/d96a6b8bcc7439fa7e3876207aa0a8e79c8451b6https://lists.debian.org/debian-lts-announce/2018/03/msg00011.htmlhttps://security.gentoo.org/glsa/201804-16https://usn.ubuntu.com/3592-1/https://usn.ubuntu.com/3592-2/http://www.openwall.com/lists/oss-security/2017/09/29/4https://github.com/Cisco-Talos/clamav-devel/commit/d96a6b8bcc7439fa7e3876207aa0a8e79c8451b6https://lists.debian.org/debian-lts-announce/2018/03/msg00011.htmlhttps://security.gentoo.org/glsa/201804-16https://usn.ubuntu.com/3592-1/https://usn.ubuntu.com/3592-2/
2018-03-13
Published