CVE-2018-1000085: Medium severity clamav clamav vulnerability
ClamAV version version 0.99.3 contains a Out of bounds heap memory read vulnerability in XAR parser, function xarhashcheck() that can result in Leaking of memory, may help in developing exploit chains.. This attack appear to be exploitable via The victim must scan a crafted XAR file. This vulnerability appears to have been fixed in after commit d96a6b8bcc7439fa7e3876207aa0a8e79c8451b6.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1000085?
The severity of CVE-2018-1000085 is medium.
How can I exploit CVE-2018-1000085?
You can exploit CVE-2018-1000085 by scanning a crafted XAR file.
What software versions are affected by CVE-2018-1000085?
ClamAV version 0.99.3 is affected by CVE-2018-1000085.
How can I fix CVE-2018-1000085?
Upgrade to ClamAV version 0.99.4 or later to fix CVE-2018-1000085.
Where can I find more information about CVE-2018-1000085?
You can find more information about CVE-2018-1000085 at the following references: [1](http://www.openwall.com/lists/oss-security/2017/09/29/4), [2](https://github.com/Cisco-Talos/clamav-devel/commit/d96a6b8bcc7439fa7e3876207aa0a8e79c8451b6), [3](https://lists.debian.org/debian-lts-announce/2018/03/msg00011.html).