CVE Database
/

CVE-2017-12375

Back to search

CVE-2017-12375

Published: Jan 26, 2018

Modified: Dec 2, 2024

PUBLISHED

Description

The ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a lack of input validation checking mechanisms during certain mail parsing functions (the rfc2047 function in mbox.c). An unauthenticated, remote attacker could exploit this vulnerability by sending a crafted email to the affected device. This action could cause a buffer overflow condition when ClamAV scans the malicious email, allowing the attacker to potentially cause a DoS condition on an affected device.

VendorProductVersions

n/a

ClamAV AntiVirus software versions 0.99.2 and prior

affected
ClamAV AntiVirus software versions 0.99.2 and prior

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now