USN-3393-1
Dashboard / Vulnerabilities / USN-3393-1
USN-3393-1
Summary: clamav vulnerabilities
Details: It was discovered that ClamAV incorrectly handled parsing certain e-mail messages. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2017-6418) It was discovered that ClamAV incorrectly handled certain malformed CHM files. A remote attacker could use this issue to cause ClamAV to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 14.04 LTS. In the default installation, attackers would be isolated by the ClamAV AppArmor profile. (CVE-2017-6419) It was discovered that ClamAV incorrectly handled parsing certain PE files with WWPack compression. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2017-6420)
References: https://ubuntu.com/security/notices/USN-3393-1, https://ubuntu.com/security/CVE-2017-6418, https://ubuntu.com/security/CVE-2017-6419, https://ubuntu.com/security/CVE-2017-6420
Affected packages
Package
Name: clamav
Purl: pkg:deb/ubuntu/[email protected]+addedllvm-0ubuntu0.14.04.2?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
