CVE-2017-12377

NameCVE-2017-12377
DescriptionClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or potentially execute arbitrary code on an affected device. The vulnerability is due to improper input validation checking mechanisms in mew packet files sent to an affected device. A successful exploit could cause a heap-based buffer over-read condition in mew.c when ClamAV scans the malicious file, allowing the attacker to cause a DoS condition or potentially execute arbitrary code on the affected device.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-1261-1
NVD severityhigh (attack range: remote)
Debian Bugs888484

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
clamav (PTS)jessie0.100.0+dfsg-0+deb8u1fixed
jessie (security)0.100.3+dfsg-0+deb8u1fixed
stretch0.100.3+dfsg-0+deb9u1fixed
bullseye, sid, buster0.101.2+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
clamavsource(unstable)0.99.3~beta2+dfsg-1high888484
clamavsourcejessie0.99.2+dfsg-0+deb8u3high
clamavsourcestretch0.99.2+dfsg-6+deb9u1high
clamavsourcewheezy0.99.2+dfsg-0+deb7u4highDLA-1261-1

Notes

http://blog.clamav.net/2018/01/clamav-0993-has-been-released.html
https://bugzilla.clamav.net/show_bug.cgi?id=11943
https://github.com/vrtadmin/clamav-devel/commit/38da4800bfb2d6b13579950b6543302d13e3015c
https://github.com/vrtadmin/clamav-devel/commit/e887f113242ffcb0ea8735c3f567c6be77f382d6

Search for package or bug name: Reporting problems