2018年3月15日 星期四

[USN-3592-2] ClamAV vulnerabilities

It was discovered that ClamAV incorrectly handled parsing certain PDF files. A remote attacker could use this issue to cause ClamAV to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2018-0202)

 Hanno Böck discovered that ClamAV incorrectly handled parsing certain XAR files. A remote attacker could use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2018-1000085)

References:
  https://usn.ubuntu.com/usn/usn-3592-2
  https://usn.ubuntu.com/usn/usn-3592-1
  CVE-2018-0202, CVE-2018-1000085

沒有留言:

張貼留言