A vulnerability in ClamAV versions prior to 0.100.2 could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to an error related to the MEW unpacker within the "unmew11()" function (libclamav/mew.c), which can be exploited to trigger an invalid read memory access via a specially crafted EXE file.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade clamav | Nov 29, 2018 | Oct 15, 2018 |
| Amazon_linux | — | Upgrade clamav | Jan 12, 2019 | Oct 3, 2018 |
| Debian | — | Upgrade clamav | Feb 19, 2019 | Oct 15, 2018 |
| Freebsd | — | Upgrade clamav | Oct 4, 2018 | Oct 3, 2018 |
| Gentoo Linux | — | Upgrade app-antivirus/clamav. | Apr 12, 2019 | Oct 15, 2018 |
| Suse | — | Upgrade libfreshclam2Upgrade libclamav7Upgrade clamavUpgrade clamav-develUpgrade libclammspack0Upgrade libclamav9 | Oct 24, 2018 | Oct 3, 2018 |
| Ubuntu | — | Upgrade clamav | Oct 18, 2018 | Oct 3, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub