Denial of Service Vulnerability in ClamAV AntiVirus Software
CVE-2017-12379
9.8CRITICAL
Key Information:
- Vendor
- Debian
- Vendor
- CVE Published:
- 26 January 2018
Summary
ClamAV AntiVirus software versions 0.99.2 and earlier contain a vulnerability that could allow an unauthenticated, remote attacker to trigger a denial of service condition or potentially execute arbitrary code. This vulnerability arises from insufficient input validation during the message parsing process. An attacker could exploit the flaw by sending a specially crafted email designed to initiate a buffer overflow in the message handling function, which may result in the compromise of the affected system's stability or security.
Affected Version(s)
ClamAV AntiVirus software 0.99.2 and prior ClamAV AntiVirus software versions 0.99.2 and prior
References
EPSS Score
15% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved