2017-11-08
ALT-BU-2017-3486-1
Branch p7 update bulletin.
Closed vulnerabilities
Published: 2017-08-07
BDU:2017-01850
Уязвимость функции wwunpack (libclamav/wwunpack.c) средства антивирусной защиты Clam Antivirus, позволяющая нарушителю вызвать отказ в обслуживании
Severity: MEDIUM (4.3)
References:
Published: 2017-08-07
BDU:2017-01851
Уязвимость компонента libclamav/message.c средства антивирусной защиты Clam Antivirus, позволяющая нарушителю вызвать отказ в обслуживании
Severity: MEDIUM (4.3)
References:
Published: 2017-08-07
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2017-6418
libclamav/message.c in ClamAV 0.99.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted e-mail message.
Severity: MEDIUM (5.5)
Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
References:
- 100154
- 100154
- https://bugzilla.clamav.net/show_bug.cgi?id=11797
- https://bugzilla.clamav.net/show_bug.cgi?id=11797
- https://github.com/varsleak/varsleak-vul/blob/master/clamav-vul/heap-overflow/clamav_email_crash.md
- https://github.com/varsleak/varsleak-vul/blob/master/clamav-vul/heap-overflow/clamav_email_crash.md
- https://github.com/vrtadmin/clamav-devel/commit/586a5180287262070637c8943f2f7efd652e4a2c
- https://github.com/vrtadmin/clamav-devel/commit/586a5180287262070637c8943f2f7efd652e4a2c
- GLSA-201804-16
- GLSA-201804-16
Published: 2017-08-07
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2017-6420
The wwunpack function in libclamav/wwunpack.c in ClamAV 0.99.2 allows remote attackers to cause a denial of service (use-after-free) via a crafted PE file with WWPack compression.
Severity: MEDIUM (5.5)
Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
References:
- https://bugzilla.clamav.net/show_bug.cgi?id=11798
- https://bugzilla.clamav.net/show_bug.cgi?id=11798
- https://github.com/varsleak/varsleak-vul/blob/master/clamav-vul/use-after-free/clamav-use-after-free-pe.md
- https://github.com/varsleak/varsleak-vul/blob/master/clamav-vul/use-after-free/clamav-use-after-free-pe.md
- https://github.com/vrtadmin/clamav-devel/commit/dfc00cd3301a42b571454b51a6102eecf58407bc
- https://github.com/vrtadmin/clamav-devel/commit/dfc00cd3301a42b571454b51a6102eecf58407bc
- GLSA-201804-16
- GLSA-201804-16
Closed bugs
clamscan не видит файлов и каталогов, имеющих inode >2^32