Bugzilla – Full Text Bug Listing |
Summary: | VUL-0: CVE-2017-11423: clamav: The cabd_read_string function in mspack/cabd.c in libmspack 0.5alpha, as used inClamAV 0.99.2, allows remote attackers to cause a denial of service | ||
---|---|---|---|
Product: | [Novell Products] SUSE Security Incidents | Reporter: | Victor Pereira <vpereira> |
Component: | Incidents | Assignee: | Security Team bot <security-team> |
Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
Severity: | Normal | ||
Priority: | P3 - Medium | CC: | max, smash_bz, vcizek |
Version: | unspecified | ||
Target Milestone: | --- | ||
Hardware: | Other | ||
OS: | Other | ||
URL: | https://smash.suse.de/issue/188722/ | ||
Whiteboard: | CVSSv2:SUSE:CVE-2017-11423:1.7:(AV:L/AC:L/Au:S/C:N/I:N/A:P) CVSSv3:SUSE:CVE-2017-11423:5.5:(AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H) maint:released:sle10-sp3:63958 maint:released:sle10-sp3:63992 | ||
Found By: | Security Response Team | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Description
Victor Pereira
2017-07-19 11:41:48 UTC
This is an autogenerated message for OBS integration: This bug (1049423) was mentioned in https://build.opensuse.org/request/show/569980 Factory / clamav Fixed in version 0.99.3 (in the running maintenance update). Reassigning to the security team. SUSE-SU-2018:0254-1: An update that fixes 11 vulnerabilities is now available. Category: security (important) Bug References: 1049423,1052448,1052449,1052466,1077732 CVE References: CVE-2017-11423,CVE-2017-12374,CVE-2017-12375,CVE-2017-12376,CVE-2017-12377,CVE-2017-12378,CVE-2017-12379,CVE-2017-12380,CVE-2017-6418,CVE-2017-6419,CVE-2017-6420 Sources used: SUSE Linux Enterprise Server 11-SP4 (src): clamav-0.99.3-0.20.3.2 SUSE Linux Enterprise Server 11-SP3-LTSS (src): clamav-0.99.3-0.20.3.2 SUSE Linux Enterprise Point of Sale 11-SP3 (src): clamav-0.99.3-0.20.3.2 SUSE Linux Enterprise Debuginfo 11-SP4 (src): clamav-0.99.3-0.20.3.2 SUSE Linux Enterprise Debuginfo 11-SP3 (src): clamav-0.99.3-0.20.3.2 SUSE-SU-2018:0255-1: An update that fixes 11 vulnerabilities is now available. Category: security (important) Bug References: 1040662,1049423,1052448,1052449,1052466,1077732 CVE References: CVE-2017-11423,CVE-2017-12374,CVE-2017-12375,CVE-2017-12376,CVE-2017-12377,CVE-2017-12378,CVE-2017-12379,CVE-2017-12380,CVE-2017-6418,CVE-2017-6419,CVE-2017-6420 Sources used: SUSE OpenStack Cloud 6 (src): clamav-0.99.3-33.5.1 SUSE Linux Enterprise Server for SAP 12-SP1 (src): clamav-0.99.3-33.5.1 SUSE Linux Enterprise Server for SAP 12 (src): clamav-0.99.3-33.5.1 SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (src): clamav-0.99.3-33.5.1 SUSE Linux Enterprise Server 12-SP3 (src): clamav-0.99.3-33.5.1 SUSE Linux Enterprise Server 12-SP2 (src): clamav-0.99.3-33.5.1 SUSE Linux Enterprise Server 12-SP1-LTSS (src): clamav-0.99.3-33.5.1 SUSE Linux Enterprise Server 12-LTSS (src): clamav-0.99.3-33.5.1 SUSE Linux Enterprise Desktop 12-SP3 (src): clamav-0.99.3-33.5.1 SUSE Linux Enterprise Desktop 12-SP2 (src): clamav-0.99.3-33.5.1 openSUSE-SU-2018:0258-1: An update that fixes 11 vulnerabilities is now available. Category: security (important) Bug References: 1040662,1049423,1052448,1052449,1052466,1077732 CVE References: CVE-2017-11423,CVE-2017-12374,CVE-2017-12375,CVE-2017-12376,CVE-2017-12377,CVE-2017-12378,CVE-2017-12379,CVE-2017-12380,CVE-2017-6418,CVE-2017-6419,CVE-2017-6420 Sources used: openSUSE Leap 42.3 (src): clamav-0.99.3-20.1 An update workflow for this issue was started. This issue was rated as important. Please submit fixed packages until 2018-02-05. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/63957 released An update workflow for this issue was started. This issue was rated as moderate. Please submit fixed packages until 2018-03-28. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/63991 SUSE-SU-2018:0809-1: An update that fixes 5 vulnerabilities is now available. Category: security (important) Bug References: 1045315,1049423,1052449,1082858,1083915 CVE References: CVE-2012-6706,CVE-2017-11423,CVE-2017-6419,CVE-2018-0202,CVE-2018-1000085 Sources used: SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (src): clamav-0.99.4-33.9.1 SUSE Linux Enterprise Server 12-SP3 (src): clamav-0.99.4-33.9.1 SUSE Linux Enterprise Server 12-SP2 (src): clamav-0.99.4-33.9.1 SUSE Linux Enterprise Desktop 12-SP3 (src): clamav-0.99.4-33.9.1 SUSE Linux Enterprise Desktop 12-SP2 (src): clamav-0.99.4-33.9.1 openSUSE-SU-2018:0825-1: An update that fixes 5 vulnerabilities is now available. Category: security (important) Bug References: 1045315,1049423,1052449,1082858,1083915 CVE References: CVE-2012-6706,CVE-2017-11423,CVE-2017-6419,CVE-2018-0202,CVE-2018-1000085 Sources used: openSUSE Leap 42.3 (src): clamav-0.99.4-23.1 SUSE-SU-2018:0863-1: An update that fixes 5 vulnerabilities is now available. Category: security (important) Bug References: 1045315,1049423,1052449,1082858,1083915 CVE References: CVE-2012-6706,CVE-2017-11423,CVE-2017-6419,CVE-2018-0202,CVE-2018-1000085 Sources used: SUSE Linux Enterprise Server 11-SP4 (src): clamav-0.99.4-0.20.7.2 SUSE Linux Enterprise Server 11-SP3-LTSS (src): clamav-0.99.4-0.20.7.2 SUSE Linux Enterprise Point of Sale 11-SP3 (src): clamav-0.99.4-0.20.7.2 SUSE Linux Enterprise Debuginfo 11-SP4 (src): clamav-0.99.4-0.20.7.2 SUSE Linux Enterprise Debuginfo 11-SP3 (src): clamav-0.99.4-0.20.7.2 |