CVE Database
/

CVE-2017-12374

Back to search

CVE-2017-12374

Published: Jan 26, 2018

Modified: Dec 2, 2024

PUBLISHED

Description

The ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a lack of input validation checking mechanisms during certain mail parsing operations (mbox.c operations on bounce messages). If successfully exploited, the ClamAV software could allow a variable pointing to the mail body which could cause a used after being free (use-after-free) instance which may lead to a disruption of services on an affected device to include a denial of service condition.

VendorProductVersions

n/a

ClamAV AntiVirus software versions 0.99.2 and prior

affected
ClamAV AntiVirus software versions 0.99.2 and prior

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now