MGASA-2017-0291
Dashboard / Vulnerabilities / MGASA-2017-0291
Summary: Updated clamav packages fix security vulnerabilities
Details: It was discovered that ClamAV incorrectly handled parsing certain e-mail messages. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service (CVE-2017-6418). It was discovered that ClamAV incorrectly handled parsing certain PE files with WWPack compression. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service (CVE-2017-6420).
References: https://advisories.mageia.org/MGASA-2017-0291.html, https://bugs.mageia.org/show_bug.cgi?id=21555, https://usn.ubuntu.com/usn/usn-3393-1/
Affected packages
Package
Name: clamav
Purl: pkg:rpm/mageia/clamav?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
