Summary: | <app-antivirus/clamav-0.99.4: use-after-free in wwunpack function (CVE-2017-6420) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | antivirus, net-mail+disabled |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://bugzilla.redhat.com/show_bug.cgi?id=1483910 | ||
Whiteboard: | B3 [glsa+ cve] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 649314 | ||
Bug Blocks: |
Description
Agostino Sarubbo
![]() The fix (https://github.com/Cisco-Talos/clamav-devel/commit/4fe1d1852600113d7a97f8b50908bad05c5aae91#diff-f3c3a9e99ea39b9116c12365b5826cf0) is in clamav-0.99.4 (code was changed later via https://github.com/Cisco-Talos/clamav-devel/commit/e0904c51f5480e213c150fd1d24d6c27c0f64ede#diff-f3c3a9e99ea39b9116c12365b5826cf0). This issue was resolved and addressed in GLSA 201804-16 at https://security.gentoo.org/glsa/201804-16 by GLSA coordinator Aaron Bauman (b-man). |