CVE-2017-12380

NameCVE-2017-12380
DescriptionClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation checking mechanisms in mbox.c during certain mail parsing functions of the ClamAV software. An unauthenticated, remote attacker could exploit this vulnerability by sending a crafted email to the affected device. An exploit could trigger a NULL pointer dereference condition when ClamAV scans the malicious email, which may result in a DoS condition.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-1261-1
NVD severityhigh (attack range: remote)
Debian Bugs888484

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
clamav (PTS)jessie0.100.0+dfsg-0+deb8u1fixed
jessie (security)0.100.3+dfsg-0+deb8u1fixed
stretch0.100.3+dfsg-0+deb9u1fixed
bullseye, sid, buster0.101.2+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
clamavsource(unstable)0.99.3~beta2+dfsg-1high888484
clamavsourcejessie0.99.2+dfsg-0+deb8u3high
clamavsourcestretch0.99.2+dfsg-6+deb9u1high
clamavsourcewheezy0.99.2+dfsg-0+deb7u4highDLA-1261-1

Notes

http://blog.clamav.net/2018/01/clamav-0993-has-been-released.html
https://bugzilla.clamav.net/show_bug.cgi?id=11945
https://github.com/vrtadmin/clamav-devel/commit/39c89d14a61aef2958b8ea64ade1be7a5faca897

Search for package or bug name: Reporting problems