CVE-2015-2170: Medium severity ubuntu vulnerability
Published May 12, 2015
·Updated
The upx decoder in ClamAV before 0.98.7 allows remote attackers to cause a denial of service (crash) via a crafted file.
Affected Software
5 affected components
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=14.10
Canonical Ubuntu Linux=15.04
clamav clamav<=0.98.6
Remediation
Event History
May 12, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2170?
CVE-2015-2170 is classified as a moderate severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2015-2170?
To fix CVE-2015-2170, users should update ClamAV to version 0.98.7 or later.
3
What software is affected by CVE-2015-2170?
CVE-2015-2170 affects ClamAV versions up to 0.98.6 and specific versions of Ubuntu Linux including 12.04, 14.04, 14.10, and 15.04.
4
What type of vulnerability is CVE-2015-2170?
CVE-2015-2170 is a denial of service vulnerability in the upx decoder of ClamAV.
5
Can CVE-2015-2170 be exploited remotely?
Yes, CVE-2015-2170 can be exploited remotely by attackers through crafted files.