Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-11423

Опубликовано: 18 июл. 2017
Источник: debian
EPSS Низкий

Описание

The cabd_read_string function in mspack/cabd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2 and other products, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted CAB file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libmspackfixed0.6-1package
clamavfixed0.99.3~beta1+dfsg-1package
clamavfixed0.99.4+dfsg-1+deb9u1stretchpackage

Примечания

  • https://bugzilla.clamav.net/show_bug.cgi?id=11873 (not public)

  • https://github.com/kyz/libmspack/commit/17038206fcc384dcee6dd9e3a75f08fd3ddc6a38

  • https://github.com/hackerlib/hackerlib-vul/tree/master/clamav-vul

  • ClamAV: https://github.com/vrtadmin/clamav-devel/commit/ffa31264a657618a0e40c51c01e4bfc32e244d13

  • ClamaV: https://github.com/vrtadmin/clamav-devel/commit/ada5f94e5cfb04e1ac2a6f383f2184753f475b96

  • ClamAV uses the libmspack system library when available. This is the

  • case from starting from Debian Jessie. Debian Wheezy does not have

  • libmspack and thus need to have the fix as well in the src:clamav source package.

EPSS

Процентиль: 88%
0.04069
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 8 лет назад

The cabd_read_string function in mspack/cabd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2 and other products, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted CAB file.

CVSS3: 5.5
redhat
больше 8 лет назад

The cabd_read_string function in mspack/cabd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2 and other products, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted CAB file.

CVSS3: 5.5
nvd
больше 8 лет назад

The cabd_read_string function in mspack/cabd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2 and other products, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted CAB file.

CVSS3: 5.5
github
больше 3 лет назад

The cabd_read_string function in mspack/cabd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2 and other products, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted CAB file.

suse-cvrf
почти 8 лет назад

Security update for clamav

EPSS

Процентиль: 88%
0.04069
Низкий