Out-of-bounds read in ClamAV - CVE-2018-1000085

 

Out-of-bounds read in ClamAV - CVE-2018-1000085

Published: March 16, 2018 / Updated: March 22, 2018


Vulnerability identifier: #VU11136
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1000085
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated attacker to cause DoS condition on the target system.

The weakness exists in the xar_hash_check() function due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted XAR file, trick the victim into opening it, trigger out-of-bounds heap memory read and cause the service to crash.

Affected software

ClamAV
Amazon Linux AMI
Gentoo Linux
Arch Linux
Fedora
SUSE Linux
Opensuse
clamav (Alpine package)
clamav

How to mitigate CVE-2018-1000085

Install update from vendor's website.

clamav (Alpine package) - update to 0.99.4-r0
clamav - addressed in versions 0.99.4-1.el6, 0.99.4-1.el7, 0.99.4-1.fc26, 0.99.4-1.fc27

External References

Related Security Bulletins