CVE-2018-0361 PUBLISHED

ClamAV before 0.100.1 lacks a PDF object length check, resulting in an unreasonably long time to parse a relatively small file.

EPSS 0.72% · 72.3th percentile

Risk Scores

EPSS Score
0.72%
72.3th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSclamav0, 0.99.4+addedllvm-0ubuntu0.16.04.1, 0.99.3+addedllvm-0ubuntu0.16.04.1
Ubuntu:18.04:LTSclamav0.99.4+addedllvm-0ubuntu1, 0, 0.99.2+dfsg-6ubuntu2
Ubuntu:14.04:LTSclamav0.98.5+addedllvm-0ubuntu0.14.04.1, 0.98.1+dfsg-4ubuntu1.1, 0.98.1+dfsg-4ubuntu1

Timeline

References

Open in Interactive Console →