CVE-2018-15378
Summary
| CVE | CVE-2018-15378 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-10-15 17:29:00 UTC |
| Updated | 2019-10-09 23:35:00 UTC |
| Description | A vulnerability in ClamAV versions prior to 0.100.2 could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to an error related to the MEW unpacker within the "unmew11()" function (libclamav/mew.c), which can be exploited to trigger an invalid read memory access via a specially crafted EXE file. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| ClamAV: Multiple vulnerabilities (GLSA 201904-12) — Gentoo security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| Secunia Advisories |
MISC |
www.flexera.com |
Third Party Advisory |
| [SECURITY] [DLA 1553-1] clamav security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| Bug 12170 – Invalid read memory access in MEW unpacker |
CONFIRM |
bugzilla.clamav.net |
Issue Tracking, Patch, Third Party Advisory |
| USN-3789-1: ClamAV vulnerability | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| USN-3789-2: ClamAV vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| End of Support for the Secunia Community Site - Community |
SECUNIA |
secuniaresearch.flexerasoftware.com |
Permissions Required, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500093 Alpine Linux Security Update for clamav
- 503818 Alpine Linux Security Update for clamav
- 710172 Gentoo Linux ClamAV Multiple vulnerabilities (GLSA 201904-12)