Integer Overflow Vulnerability in ClamAV Affecting File Parsing
CVE-2018-0360
5.5MEDIUM
What is CVE-2018-0360?
ClamAV versions prior to 0.100.1 are susceptible to an integer overflow vulnerability when parsing specially crafted Hangul Word Processor (HWP) files. An attacker can exploit this weakness, leading to an infinite loop that may disrupt service. This issue is associated with the parsehwp3_paragraph() function in libclamav/hwp.c, highlighting the importance of updating to the patched version to safeguard systems against potential exploitation.
Affected Version(s)
ClamAV before 0.100.1 unknown ClamAV before 0.100.1 unknown
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved