Remote Code Execution Vulnerability in ClamAV by Cisco Systems
CVE-2017-6420

5.5MEDIUM

Key Information:

Vendor

Clamav

Status
Vendor
CVE Published:
7 August 2017

What is CVE-2017-6420?

The ClamAV antivirus software contains a vulnerability in the 'wwunpack' function, enabling remote attackers to trigger a denial of service condition. By crafting a malicious PE file that uses WWPack compression, attackers can exploit this flaw, potentially leading to application crashes due to improper memory handling. It is critical for users to apply updates and patches to mitigate the risk associated with this issue. For further details, review advisory notices and recommended actions provided by security experts.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.