First published: Mon Aug 07 2017(Updated: )
The wwunpack function in libclamav/wwunpack.c in ClamAV 0.99.2 allows remote attackers to cause a denial of service (use-after-free) via a crafted PE file with WWPack compression.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ClamAV | =0.99.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6420 has a severity rating indicating it can lead to a denial of service due to a use-after-free vulnerability.
To fix CVE-2017-6420, upgrade ClamAV to a version later than 0.99.2 where the vulnerability is patched.
Exploiting CVE-2017-6420 can cause ClamAV to crash, resulting in a denial of service for users.
CVE-2017-6420 affects the wwunpack function in the libclamav library of ClamAV software.
Users and systems relying on ClamAV 0.99.2 for malware detection and file scanning are primarily impacted by CVE-2017-6420.