Denial of Service Vulnerability in ClamAV AntiVirus Software by Cisco Systems
CVE-2017-12380
Key Information:
- Vendor
- Debian
- Vendor
- CVE Published:
- 26 January 2018
Summary
ClamAV AntiVirus software versions 0.99.2 and earlier are susceptible to a vulnerability that allows unauthenticated remote attackers to potentially induce a Denial of Service (DoS). This is facilitated by inadequate input validation in the mbox.c module during specific email parsing operations. When a maliciously crafted email is processed, it can lead to a NULL pointer dereference, causing the system to become unresponsive. Attackers looking to exploit this flaw can execute the attack without needing authentication, thereby posing a significant risk to systems using these versions of ClamAV.
Affected Version(s)
ClamAV AntiVirus software 0.99.2 and prior ClamAV AntiVirus software versions 0.99.2 and prior
References
EPSS Score
9% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved