ALPINE-CVE-2017-12378 PUBLISHED CVSS 5.5 MEDIUM

ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation checking mechanisms of .tar (Tape Archive) files sent to an affected device. A successful exploit could cause a checksum buffer over-read condition when ClamAV scans the malicious .tar file, potentially allowing the attacker to cause a DoS condition on the affected device.

Risk Scores

CVSS v3.0
5.5
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Alpine:v3.13clamav0.94.2-r0, 0.99.2-r6, 0.99.2-r5
Alpine:v3.9clamav0.99.2-r6, 0, 0.94.2-r0
Alpine:v3.11clamav0.98.1-r0, 0.99.2-r6, 0.99.2-r5
Alpine:v3.8clamav0.97.6-r1, 0, 0.94.2-r0
Alpine:v3.10clamav0.94.2-r0, 0, 0.99.2-r6
Alpine:v3.12clamav0.99.2-r6, 0.99.2-r5, 0.99.2-r4

Timeline

References

Open in Interactive Console →