Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-11423

Опубликовано: 18 июл. 2017
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

The cabd_read_string function in mspack/cabd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2 and other products, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted CAB file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7libmspackWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1472776clamav: Stack-based buffer over-read in cabd_read_string function

EPSS

Процентиль: 88%
0.04069
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 8 лет назад

The cabd_read_string function in mspack/cabd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2 and other products, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted CAB file.

CVSS3: 5.5
nvd
больше 8 лет назад

The cabd_read_string function in mspack/cabd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2 and other products, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted CAB file.

CVSS3: 5.5
debian
больше 8 лет назад

The cabd_read_string function in mspack/cabd.c in libmspack 0.5alpha, ...

CVSS3: 5.5
github
больше 3 лет назад

The cabd_read_string function in mspack/cabd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2 and other products, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted CAB file.

suse-cvrf
почти 8 лет назад

Security update for clamav

EPSS

Процентиль: 88%
0.04069
Низкий

5.5 Medium

CVSS3