Summary: | <app-antivirus/clamav-0.100.2: denial-of-service in MEW unpacking feature (CVE-2018-15378) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | GLSAMaker/CVETool Bot <glsamaker> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | antivirus, net-mail+disabled |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://blog.clamav.net/2018/10/clamav-01002-has-been-released.html | ||
Whiteboard: | A3 [glsa+ cve] | ||
Package list: | Runtime testing required: | --- |
Description
GLSAMaker/CVETool Bot
2018-10-06 17:44:05 UTC
A flaw was found in ClamAV's MEW unpacking feature that could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition on an affected device. Package is not yet ready for stabilization, we will fix some additional issues first. @Whissi are you referring to the other built-in lib? This issue was resolved and addressed in GLSA 201904-12 at https://security.gentoo.org/glsa/201904-12 by GLSA coordinator Aaron Bauman (b-man). |