Vulnerability CVE-2018-15378: Information

Description

A vulnerability in ClamAV versions prior to 0.100.2 could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to an error related to the MEW unpacker within the "unmew11()" function (libclamav/mew.c), which can be exploited to trigger an invalid read memory access via a specially crafted EXE file.

Severity: MEDIUM (5.5) Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Published: Oct. 15, 2018
Modified: Oct. 10, 2019
Error type identifier: CWE-125

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
clamavsisyphus0.100.2-alt10.103.8-alt1ALT-PU-2018-2498-1215109Fixed
clamavp100.100.2-alt10.103.8-alt1ALT-PU-2018-2498-1215109Fixed
clamavp90.100.2-alt10.103.8-alt1ALT-PU-2018-2498-1215109Fixed
clamavp80.100.2-alt0.M80P.10.103.8-alt1ALT-PU-2018-2506-1215132Fixed
clamavc10f10.100.2-alt10.103.8-alt1ALT-PU-2018-2498-1215109Fixed
clamavc9f20.100.2-alt10.103.8-alt1ALT-PU-2018-2498-1215109Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
83000
  • Permissions Required
  • Third Party Advisory
https://bugzilla.clamav.net/show_bug.cgi?id=12170
  • Issue Tracking
  • Patch
  • Third Party Advisory
USN-3789-1
  • Third Party Advisory
USN-3789-2
  • Third Party Advisory
[debian-lts-announce] 20181024 [SECURITY] [DLA 1553-1] clamav security update
  • Mailing List
  • Third Party Advisory
https://www.flexera.com/company/secunia-research/advisories/SR-2018-23.html
  • Third Party Advisory
GLSA-201904-12
  • Third Party Advisory
    1. Configuration 1

      cpe:2.3:a:clamav:clamav:*:*:*:*:*:*:*:*
      End excliding
      0.100.2

      Configuration 2

      cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*