CVE-2016-1371: Medium severity ubuntu vulnerability
Published Oct 3, 2016
·Updated
ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted mew packer executable.
Affected Software
4 affected components
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
clamav clamav<=0.99.1
Event History
Oct 3, 2016
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1371?
CVE-2016-1371 has a severity rating of medium due to its potential for denial of service.
2
How do I fix CVE-2016-1371?
To fix CVE-2016-1371, upgrade ClamAV to version 0.99.2 or later.
3
What systems are affected by CVE-2016-1371?
CVE-2016-1371 affects ClamAV versions up to 0.99.1 and Ubuntu versions 12.04, 14.04, and 16.04.
4
What type of vulnerability is CVE-2016-1371?
CVE-2016-1371 is a denial of service vulnerability that allows remote attackers to crash the application.
5
Can CVE-2016-1371 be exploited remotely?
Yes, CVE-2016-1371 can be exploited remotely using a crafted mew packer executable.