Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-1000085

Опубликовано: 13 мар. 2018
Источник: ubuntu
Приоритет: medium
CVSS2: 4.3
CVSS3: 5.5

Описание

ClamAV version version 0.99.3 contains a Out of bounds heap memory read vulnerability in XAR parser, function xar_hash_check() that can result in Leaking of memory, may help in developing exploit chains.. This attack appear to be exploitable via The victim must scan a crafted XAR file. This vulnerability appears to have been fixed in after commit d96a6b8bcc7439fa7e3876207aa0a8e79c8451b6.

РелизСтатусПримечание
artful

released

0.99.4+addedllvm-0ubuntu0.17.10.1
devel

released

0.99.4+addedllvm-0ubuntu1
esm-infra-legacy/trusty

released

0.99.4+addedllvm-0ubuntu0.14.04.1
esm-infra/xenial

released

0.99.4+addedllvm-0ubuntu0.16.04.1
precise/esm

not-affected

0.99.4+addedllvm-0ubuntu0.12.04.2
trusty

released

0.99.4+addedllvm-0ubuntu0.14.04.1
trusty/esm

released

0.99.4+addedllvm-0ubuntu0.14.04.1
upstream

released

0.99.4
xenial

released

0.99.4+addedllvm-0ubuntu0.16.04.1

Показывать по

4.3 Medium

CVSS2

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
nvd
почти 8 лет назад

ClamAV version version 0.99.3 contains a Out of bounds heap memory read vulnerability in XAR parser, function xar_hash_check() that can result in Leaking of memory, may help in developing exploit chains.. This attack appear to be exploitable via The victim must scan a crafted XAR file. This vulnerability appears to have been fixed in after commit d96a6b8bcc7439fa7e3876207aa0a8e79c8451b6.

CVSS3: 5.5
debian
почти 8 лет назад

ClamAV version version 0.99.3 contains a Out of bounds heap memory rea ...

CVSS3: 5.5
github
больше 3 лет назад

ClamAV version version 0.99.3 contains a Out of bounds heap memory read vulnerability in XAR parser, function xar_hash_check() that can result in Leaking of memory, may help in developing exploit chains.. This attack appear to be exploitable via The victim must scan a crafted XAR file. This vulnerability appears to have been fixed in after commit d96a6b8bcc7439fa7e3876207aa0a8e79c8451b6.

suse-cvrf
больше 7 лет назад

Security update for clamav

suse-cvrf
больше 7 лет назад

Security update for clamav

4.3 Medium

CVSS2

5.5 Medium

CVSS3