Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian 7 Wheezy: Critical Clamav DoS Vulnerability DLA-1105-1 Released

debian lts
Calendar Grey September 22, 2017
Dist Debian Esm H88
Latest clamav security patch addresses denial of service flaws arising from several vulnerabilities impacting Debian Wheezy.
clamav is vulnerable to multiple issues that can lead to denial of service when processing untrusted content

Summary

CVE-2017-6418

out-of-bounds read in libclamav/message.c, allowing remote attackers to cause a denial of service via a crafted e-mail message.

CVE-2017-6420

use-after-free in the wwunpack function (libclamav/wwunpack.c), allowing
remote attackers to cause a denial of service via a crafted PE file with
WWPack compression.

For Debian 7 "Wheezy", these problems have been fixed in version
0.99.2+dfsg-0+deb7u3.

We recommend that you upgrade your clamav packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

Package: clamav
Version: 0.99.2+dfsg-0+deb7u3
CVE ID: CVE-2017-6418 CVE-2017-6420

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here