#VU15374 Buffer over-read in ClamAV - CVE-2018-15378
Published: October 16, 2018
ClamAV
ClamAV
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition related to MEW unpacker within the unmew11() function in libclamav/mew.c. A remote attacker can create a specially crafted EXE file, pass it to vulnerable application and trigger invalid memory read.