Out-of-bounds read in ClamAV - CVE-2018-0202
Published: March 28, 2018
Vulnerability identifier: #VU11302
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0202
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to improper input validation checking mechanisms when handling Portable Document Format files. A remote attacker can send a specially .pdf file, trigger out-of-bounds read and cause the service to crash.
The weakness exists due to improper input validation checking mechanisms when handling Portable Document Format files. A remote attacker can send a specially .pdf file, trigger out-of-bounds read and cause the service to crash.
Affected software
ClamAV
Amazon Linux AMI
Gentoo Linux
Fedora
SUSE Linux
Opensuse
clamav (Alpine package)
clamav
Amazon Linux AMI
Gentoo Linux
Fedora
SUSE Linux
Opensuse
clamav (Alpine package)
clamav
How to mitigate CVE-2018-0202
Update to version 0.99.4.
clamav (Alpine package) - update to 0.99.4-r0
clamav - addressed in versions 0.99.4-1.el6, 0.99.4-1.el7, 0.99.4-1.fc26, 0.99.4-1.fc27
clamav - addressed in versions 0.99.4-1.el6, 0.99.4-1.el7, 0.99.4-1.fc26, 0.99.4-1.fc27
External References
Related Security Bulletins
- Amazon Linux AMI update for clamav
- SUSE Linux update for clamav
- SUSE Linux update for clamav
- Gentoo update for ClamAV
- OpenSUSE Linux update for clamav
- Out-of-bounds read in clamav (Alpine package)
- Fedora EPEL 6 update for clamav
- Fedora EPEL 7 update for clamav
- Fedora 27 update for clamav
- Fedora 26 update for clamav