Описание
ClamAV versions prior to 0.101.3 are susceptible to a zip bomb vulnerability where an unauthenticated attacker can cause a denial of service condition by sending crafted messages to an affected system.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
clamav | fixed | 0.101.4+dfsg-1 | package | |
clamav | fixed | 0.101.4+dfsg-0+deb10u1 | buster | package |
clamav | fixed | 0.101.4+dfsg-0+deb9u1 | stretch | package |
Примечания
https://www.openwall.com/lists/oss-security/2019/08/06/3
https://bugzilla.clamav.net/show_bug.cgi?id=12356
Partially adressed already in 0.101.2+dfsg-3 but incomplete.
https://blog.clamav.net/2019/08/clamav-01014-security-patch-release-has.html
EPSS
Связанные уязвимости
ClamAV versions prior to 0.101.3 are susceptible to a zip bomb vulnerability where an unauthenticated attacker can cause a denial of service condition by sending crafted messages to an affected system.
ClamAV versions prior to 0.101.3 are susceptible to a zip bomb vulnerability where an unauthenticated attacker can cause a denial of service condition by sending crafted messages to an affected system.
ClamAV versions prior to 0.101.3 are susceptible to a zip bomb vulnerability where an unauthenticated attacker can cause a denial of service condition by sending crafted messages to an affected system.
Уязвимость пакета антивирусных программ ClamAV, позволяющая нарушителю вызвать отказ в обслуживании
EPSS