Bug 1101412 - (CVE-2018-0361) VUL-0: CVE-2018-0361: clamav: Missing PDF object length check results in an unreasonably long time to parse a relatively small file
(CVE-2018-0361)
VUL-0: CVE-2018-0361: clamav: Missing PDF object length check results in an u...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/210727/
CVSSv3:SUSE:CVE-2018-0361:5.3:(AV:N/A...
:
Depends on: 1101654
Blocks:
  Show dependency treegraph
 
Reported: 2018-07-17 07:19 UTC by Johannes Segitz
Modified: 2020-07-27 02:08 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2018-07-17 07:19:45 UTC
CVE-2018-0361

ClamAV before 0.100.1 lacks a PDF object length check, resulting in an
unreasonably long time to parse a relatively small file.

Probably fixed by 5090e3b8b

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-0361
Comment 1 Swamp Workflow Management 2018-07-17 22:20:09 UTC
This is an autogenerated message for OBS integration:
This bug (1101412) was mentioned in
https://build.opensuse.org/request/show/623520 Factory / clamav
Comment 3 Swamp Workflow Management 2018-07-18 07:00:10 UTC
This is an autogenerated message for OBS integration:
This bug (1101412) was mentioned in
https://build.opensuse.org/request/show/623554 15.0+42.3 / clamav
Comment 4 Swamp Workflow Management 2018-07-27 13:01:11 UTC
An update workflow for this issue was started.
This issue was rated as important.
Please submit fixed packages until 2018-08-03.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/64096
Comment 5 Swamp Workflow Management 2018-07-30 12:10:09 UTC
This is an autogenerated message for OBS integration:
This bug (1101412) was mentioned in
https://build.opensuse.org/request/show/626469 Factory / clamav
Comment 8 Swamp Workflow Management 2018-07-31 13:10:09 UTC
This is an autogenerated message for OBS integration:
This bug (1101412) was mentioned in
https://build.opensuse.org/request/show/626690 Factory / clamav
Comment 9 Swamp Workflow Management 2018-08-07 13:09:04 UTC
SUSE-SU-2018:2230-1: An update that solves two vulnerabilities and has two fixes is now available.

Category: security (moderate)
Bug References: 1101410,1101412,1101654,1103040
CVE References: CVE-2018-0360,CVE-2018-0361
Sources used:
SUSE Linux Enterprise Module for Basesystem 15 (src):    clamav-0.100.1-3.3.1
Comment 10 Swamp Workflow Management 2018-08-07 13:10:32 UTC
SUSE-SU-2018:2232-1: An update that solves two vulnerabilities and has two fixes is now available.

Category: security (moderate)
Bug References: 1101410,1101412,1101654,1103040
CVE References: CVE-2018-0360,CVE-2018-0361
Sources used:
SUSE Linux Enterprise Server 11-SP4 (src):    clamav-0.100.1-0.20.15.1
SUSE Linux Enterprise Server 11-SP3-LTSS (src):    clamav-0.100.1-0.20.15.1
SUSE Linux Enterprise Point of Sale 11-SP3 (src):    clamav-0.100.1-0.20.15.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    clamav-0.100.1-0.20.15.1
SUSE Linux Enterprise Debuginfo 11-SP3 (src):    clamav-0.100.1-0.20.15.1
Comment 11 Swamp Workflow Management 2018-08-08 22:25:38 UTC
openSUSE-SU-2018:2259-1: An update that solves two vulnerabilities and has two fixes is now available.

Category: security (moderate)
Bug References: 1101410,1101412,1101654,1103040
CVE References: CVE-2018-0360,CVE-2018-0361
Sources used:
openSUSE Leap 15.0 (src):    clamav-0.100.1-lp150.2.3.1
Comment 12 Swamp Workflow Management 2018-08-14 16:11:05 UTC
SUSE-SU-2018:2323-1: An update that solves four vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 1082858,1101410,1101412,1101654,1103040
CVE References: CVE-2018-0360,CVE-2018-0361,CVE-2018-1000085,CVE-2018-14679
Sources used:
SUSE OpenStack Cloud 7 (src):    clamav-0.100.1-33.15.2
SUSE Linux Enterprise Server for SAP 12-SP2 (src):    clamav-0.100.1-33.15.2
SUSE Linux Enterprise Server for SAP 12-SP1 (src):    clamav-0.100.1-33.15.2
SUSE Linux Enterprise Server 12-SP3 (src):    clamav-0.100.1-33.15.2
SUSE Linux Enterprise Server 12-SP2-LTSS (src):    clamav-0.100.1-33.15.2
SUSE Linux Enterprise Server 12-SP1-LTSS (src):    clamav-0.100.1-33.15.2
SUSE Linux Enterprise Server 12-LTSS (src):    clamav-0.100.1-33.15.2
SUSE Linux Enterprise Desktop 12-SP3 (src):    clamav-0.100.1-33.15.2
SUSE Enterprise Storage 4 (src):    clamav-0.100.1-33.15.2
Comment 13 Swamp Workflow Management 2018-08-17 10:32:26 UTC
openSUSE-SU-2018:2406-1: An update that solves four vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 1082858,1101410,1101412,1101654,1103040
CVE References: CVE-2018-0360,CVE-2018-0361,CVE-2018-1000085,CVE-2018-14679
Sources used:
openSUSE Leap 42.3 (src):    clamav-0.100.1-29.1
Comment 14 Marcus Meissner 2018-09-07 11:52:50 UTC
released
Comment 15 Swamp Workflow Management 2018-10-18 17:36:26 UTC
SUSE-SU-2018:2323-2: An update that solves four vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 1082858,1101410,1101412,1101654,1103040
CVE References: CVE-2018-0360,CVE-2018-0361,CVE-2018-1000085,CVE-2018-14679
Sources used:
SUSE Linux Enterprise Server 12-SP2-BCL (src):    clamav-0.100.1-33.15.2