USN-3722-5
Dashboard / Vulnerabilities / USN-3722-5
USN-3722-5
Summary: clamav regression
Details: USN-3722-1 fixed vulnerabilities in ClamAV. The new package introduced an issue which caused dpkg-reconfigure to enter an infinite loop. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that ClamAV incorrectly handled parsing certain HWP files. A remote attacker could use this issue to cause ClamAV to hang, resulting in a denial of service. (CVE-2018-0360) It was discovered that ClamAV incorrectly handled parsing certain PDF files. A remote attacker could use this issue to cause ClamAV to hang, resulting in a denial of service. (CVE-2018-0361)
Affected packages
Package
Name: clamav
Purl: pkg:deb/ubuntu/[email protected]+dfsg-1ubuntu0.14.04.4?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
