Vulnerability Description
libclamav/message.c in ClamAV 0.99.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted e-mail message.
CVSS Score
5.5
MEDIUM
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Clamav | Clamav | 0.99.2 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/100154
- https://bugzilla.clamav.net/show_bug.cgi?id=11797Permissions Required
- https://github.com/varsleak/varsleak-vul/blob/master/clamav-vul/heap-overflow/clThird Party Advisory
- https://github.com/vrtadmin/clamav-devel/commit/586a5180287262070637c8943f2f7efdIssue TrackingPatchThird Party Advisory
- https://security.gentoo.org/glsa/201804-16
- http://www.securityfocus.com/bid/100154
- https://bugzilla.clamav.net/show_bug.cgi?id=11797Permissions Required
- https://github.com/varsleak/varsleak-vul/blob/master/clamav-vul/heap-overflow/clThird Party Advisory
- https://github.com/vrtadmin/clamav-devel/commit/586a5180287262070637c8943f2f7efdIssue TrackingPatchThird Party Advisory
- https://security.gentoo.org/glsa/201804-16
FAQ
What is CVE-2017-6418?
CVE-2017-6418 is a vulnerability with a CVSS score of 5.5 (MEDIUM). libclamav/message.c in ClamAV 0.99.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted e-mail message.
How severe is CVE-2017-6418?
CVE-2017-6418 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-6418?
Check the references section above for vendor advisories and patch information. Affected products include: Clamav Clamav.