ClamAV version version 0.99.3 contains a Out of bounds heap memory read vulnerability in XAR parser, function xar_hash_check() that can result in Leaking of memory, may help in developing exploit chains.. This attack appear to be exploitable via The victim must scan a crafted XAR file. This vulnerability appears to have been fixed in after commit d96a6b8bcc7439fa7e3876207aa0a8e79c8451b6.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade clamav | Apr 13, 2018 | Mar 13, 2018 |
| Amazon_linux | — | Upgrade clamav | Mar 25, 2018 | Mar 13, 2018 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Mar 13, 2018 |
| Debian | — | Upgrade clamav | Feb 19, 2019 | Mar 13, 2018 |
| Gentoo Linux | — | Upgrade app-antivirus/clamav. | Apr 23, 2018 | Mar 13, 2018 |
| Suse | — | Upgrade libclamav7Upgrade libclammspack0Upgrade clamav-develUpgrade libclamav9Upgrade libfreshclam2Upgrade clamav | Mar 27, 2018 | Mar 13, 2018 |
| Ubuntu | — | Upgrade clamav | Apr 25, 2018 | Mar 8, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub