[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2019-1146 --- clamav

ID: oval:org.secpod.oval:def:1600971Date: (C)2019-01-16   (M)2022-10-27
Class: PATCHFamily: unix




An issue was discovered in kwajd_read_headers in mspack/kwajd.c in libmspack before 0.7alpha. Bad KWAJ file header extensions could cause a one or two byte overwrite.An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER macro for CHM decompression.An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. It does not reject blank CHM filenames.A vulnerability in ClamAV versions prior to 0.100.2 could allow an attacker to cause a denial of service condition. The vulnerability is due to an error related to the MEW unpacker within the "unmew11" function , which can be exploited to trigger an invalid read memory access via a specially crafted EXE file.An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the CHM PMGI/PMGL chunk number validity checks, which could lead to denial of service .

Platform:
Amazon Linux AMI
Product:
clamav
Reference:
ALAS-2019-1146
CVE-2018-14679
CVE-2018-14682
CVE-2018-15378
CVE-2018-14680
CVE-2018-14681
CVE    5
CVE-2018-14682
CVE-2018-15378
CVE-2018-14681
CVE-2018-14680
...
CPE    128
cpe:/a:clamav:clamav:0.95:src2
cpe:/a:clamav:clamav:0.81:rc1
cpe:/a:clamav:clamav:0.95:src1
cpe:/a:clamav:clamav:0.21
...

© SecPod Technologies