Integer Overflow Vulnerability in ClamAV Affecting File Parsing
CVE-2018-0360

5.5MEDIUM

Key Information:

Vendor

Clamav

Vendor
CVE Published:
16 July 2018

What is CVE-2018-0360?

ClamAV versions prior to 0.100.1 are susceptible to an integer overflow vulnerability when parsing specially crafted Hangul Word Processor (HWP) files. An attacker can exploit this weakness, leading to an infinite loop that may disrupt service. This issue is associated with the parsehwp3_paragraph() function in libclamav/hwp.c, highlighting the importance of updating to the patched version to safeguard systems against potential exploitation.

Affected Version(s)

ClamAV before 0.100.1 unknown ClamAV before 0.100.1 unknown

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.