Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-12379

Опубликовано: 26 янв. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 10
CVSS3: 9.8

Описание

ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or potentially execute arbitrary code on an affected device. The vulnerability is due to improper input validation checking mechanisms in the message parsing function on an affected system. An unauthenticated, remote attacker could exploit this vulnerability by sending a crafted email to the affected device. This action could cause a messageAddArgument (in message.c) buffer overflow condition when ClamAV scans the malicious email, allowing the attacker to potentially cause a DoS condition or execute arbitrary code on an affected device.

РелизСтатусПримечание
artful

released

0.99.3+addedllvm-0ubuntu0.17.10.1
devel

released

0.99.3+addedllvm-0ubuntu1
esm-infra-legacy/trusty

released

0.99.3+addedllvm-0ubuntu0.14.04.1
esm-infra/xenial

released

0.99.3+addedllvm-0ubuntu0.16.04.1
precise/esm

not-affected

0.99.3+addedllvm-0ubuntu0.12.04.1
trusty

released

0.99.3+addedllvm-0ubuntu0.14.04.1
trusty/esm

released

0.99.3+addedllvm-0ubuntu0.14.04.1
upstream

released

0.99.3
xenial

released

0.99.3+addedllvm-0ubuntu0.16.04.1

Показывать по

EPSS

Процентиль: 92%
0.08048
Низкий

10 Critical

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
около 8 лет назад

ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or potentially execute arbitrary code on an affected device. The vulnerability is due to improper input validation checking mechanisms in the message parsing function on an affected system. An unauthenticated, remote attacker could exploit this vulnerability by sending a crafted email to the affected device. This action could cause a messageAddArgument (in message.c) buffer overflow condition when ClamAV scans the malicious email, allowing the attacker to potentially cause a DoS condition or execute arbitrary code on an affected device.

CVSS3: 9.8
debian
около 8 лет назад

ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerab ...

CVSS3: 9.8
github
больше 3 лет назад

ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or potentially execute arbitrary code on an affected device. The vulnerability is due to improper input validation checking mechanisms in the message parsing function on an affected system. An unauthenticated, remote attacker could exploit this vulnerability by sending a crafted email to the affected device. This action could cause a messageAddArgument (in message.c) buffer overflow condition when ClamAV scans the malicious email, allowing the attacker to potentially cause a DoS condition or execute arbitrary code on an affected device.

CVSS3: 9.8
fstec
больше 8 лет назад

Уязвимость функции messageAddArgument (message.c) средства антивирусной защиты Clam Antivirus, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код

suse-cvrf
около 8 лет назад

Security update for clamav

EPSS

Процентиль: 92%
0.08048
Низкий

10 Critical

CVSS2

9.8 Critical

CVSS3