Stack-based buffer over-read in ClamAV - CVE-2017-11423

 

Stack-based buffer over-read in ClamAV - CVE-2017-11423

Published: March 18, 2018 / Updated: March 22, 2018


Vulnerability identifier: #VU11217
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-11423
CWE-ID: CWE-126
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists in the cabd_read_string function due to stack-based buffer over-read. A remote attacker can send a specially crafted CAB file, trick the victim into opening it, trigger memory corruption and cause the service to crash.


Affected software

ClamAV
Arch Linux
Debian Linux
Amazon Linux AMI
Gentoo Linux
Fedora
SUSE Linux
Ubuntu
Opensuse
a2ps (Alpine package)
libmspack
clamav

How to mitigate CVE-2017-11423

Update to version 0.99.3.

a2ps (Alpine package) - update to 4.14-r7
libmspack - addressed in versions 0.6-0.1.alpha.el6, 0.6-0.1.alpha.el7, 0.6-0.1.alpha.fc25, 0.6-0.1.alpha.fc26, 0.6-0.1.alpha.fc27
clamav - addressed in versions 0.99.4-1.el6, 0.99.4-1.el7, 0.99.4-1.fc26, 0.99.4-1.fc27

External References

Related Security Bulletins