SB2018011723 - Fedora 27 update for clamav
Published: January 17, 2018 Updated: April 24, 2025
Security Bulletin ID
SB2018011723
Severity
Low
Patch available
YES
Number of vulnerabilities
2
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Use-after-free error (CVE-ID: CVE-2017-6420)
The vulnerability allows a rmeote attacker to cause DoS condition on the target system.The weakness exists in libclamav/wwunpack.c due to use-after-free error. A remote attacker can trick the victim into opening a specially crafted PE file with WWPack compression, trigger memory corruption and cause the service to crash.
2) Out-of-bounds read (CVE-ID: CVE-2017-6418)
The vulnerability allows a rmeote attacker to cause DoS condition on the target system.The weakness exists in libclamav/message.c due to out-of-bounds read. A remote attacker can trick the victim into opening a specially crafted e-mail message, trigger memory corruption and cause the service to crash.
Remediation
Install update from vendor's website.