CVE-2015-2668: Medium severity clamav daemon vulnerability
Published May 12, 2015
·Updated
ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted xz archive file.
Affected Software
5 affected components
clamav clamav<=0.98.6
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=14.10
Canonical Ubuntu Linux=15.1
Remediation
Event History
May 12, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2668?
CVE-2015-2668 is classified as a medium severity vulnerability that allows remote attackers to cause a denial of service.
2
How do I fix CVE-2015-2668?
To fix CVE-2015-2668, upgrade ClamAV to version 0.98.7 or later.
3
Which versions of ClamAV are affected by CVE-2015-2668?
CVE-2015-2668 affects ClamAV versions prior to 0.98.7.
4
What type of attack does CVE-2015-2668 enable?
CVE-2015-2668 enables remote denial of service attacks through a crafted xz archive.
5
Is CVE-2015-2668 relevant to Ubuntu Linux users?
Yes, CVE-2015-2668 affects certain versions of Ubuntu Linux that use vulnerable ClamAV versions.