CVE-2016-1372: Medium severity clamav daemon vulnerability
Published Oct 3, 2016
·Updated
ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted 7z file.
Affected Software
4 affected components
clamav clamav<=0.99.1
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Event History
Oct 3, 2016
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1372?
CVE-2016-1372 has a severity rating that could lead to denial of service due to application crashes.
2
How do I fix CVE-2016-1372?
To fix CVE-2016-1372, update ClamAV to version 0.99.2 or later.
3
Which versions of ClamAV are affected by CVE-2016-1372?
CVE-2016-1372 affects ClamAV versions prior to 0.99.2.
4
How can CVE-2016-1372 impact my system?
CVE-2016-1372 can lead to crashes of the ClamAV application, causing denial of service.
5
Is CVE-2016-1372 specific to any operating system?
CVE-2016-1372 can be encountered on Ubuntu systems using vulnerable versions of ClamAV.