First published: Mon Jul 16 2018(Updated: )
ClamAV before 0.100.1 lacks a PDF object length check, resulting in an unreasonably long time to parse a relatively small file.
Credit: ykramarz@cisco.com ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Clamav Clamav | <0.100.1 | |
Debian Debian Linux | =8.0 | |
ubuntu/clamav | <0.100.1+dfsg-1ubuntu0.18.04.1 | 0.100.1+dfsg-1ubuntu0.18.04.1 |
ubuntu/clamav | <0.100.1+dfsg-1ubuntu0.14.04.1 | 0.100.1+dfsg-1ubuntu0.14.04.1 |
ubuntu/clamav | <0.100.1+dfsg-1 | 0.100.1+dfsg-1 |
ubuntu/clamav | <0.100.1+dfsg-1ubuntu0.16.04.1 | 0.100.1+dfsg-1ubuntu0.16.04.1 |
debian/clamav | 0.103.10+dfsg-0+deb11u1 1.0.5+dfsg-1~deb12u1 1.3.1+dfsg-5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0361 is a vulnerability in ClamAV before version 0.100.1 that lacks a PDF object length check, resulting in an unreasonably long time to parse a relatively small file.
The severity of CVE-2018-0361 is medium, with a severity value of 3.3.
CVE-2018-0361 affects ClamAV versions before 0.100.1.
To fix CVE-2018-0361 in ClamAV, you should update to version 0.100.1 or later.
Yes, you can find more information about CVE-2018-0361 at the following references: [SecurityTracker](http://www.securitytracker.com/id/1041367), [ClamAV Blog](https://blog.clamav.net/2018/07/clamav-01001-has-been-released.html), [Debian LTS Announce](https://lists.debian.org/debian-lts-announce/2018/08/msg00020.html).