Bug 1110723 - (CVE-2018-15378) VUL-0: CVE-2018-15378: clamav: MEW unpacking DoS
(CVE-2018-15378)
VUL-0: CVE-2018-15378: clamav: MEW unpacking DoS
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other All
: P3 - Medium : Normal
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/216127/
CVSSv3:SUSE:CVE-2018-15378:7.5:(AV:N/...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2018-10-04 09:43 UTC by Andreas Stieger
Modified: 2020-04-28 15:39 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2018-10-04 09:43:54 UTC
https://blog.clamav.net/2018/10/clamav-01002-has-been-released.html
http://lists.clamav.net/pipermail/clamav-announce/2018/000033.html

     *   CVE-2018-1537
        *   Vulnerability in ClamAV's MEW unpacking feature that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
        *   Reported by Secunia Research at Flexera.

Fixed in 0.100.2

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-15378
http://lists.clamav.net/pipermail/clamav-announce/2018/000033.html
Comment 2 Swamp Workflow Management 2018-10-04 13:00:17 UTC
This is an autogenerated message for OBS integration:
This bug (1110723) was mentioned in
https://build.opensuse.org/request/show/639958 Factory / clamav
Comment 3 Swamp Workflow Management 2018-10-08 09:02:10 UTC
An update workflow for this issue was started.
This issue was rated as moderate.
Please submit fixed packages until 2018-10-22.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/64148
Comment 4 Swamp Workflow Management 2018-10-19 16:28:53 UTC
SUSE-SU-2018:3250-1: An update that fixes four vulnerabilities is now available.

Category: security (moderate)
Bug References: 1103040,1104457,1110723
CVE References: CVE-2018-14680,CVE-2018-14681,CVE-2018-14682,CVE-2018-15378
Sources used:
SUSE Linux Enterprise Module for Basesystem 15 (src):    clamav-0.100.2-3.6.4
Comment 5 Swamp Workflow Management 2018-10-23 13:16:11 UTC
openSUSE-SU-2018:3315-1: An update that fixes four vulnerabilities is now available.

Category: security (moderate)
Bug References: 1103040,1104457,1110723
CVE References: CVE-2018-14680,CVE-2018-14681,CVE-2018-14682,CVE-2018-15378
Sources used:
openSUSE Leap 15.0 (src):    clamav-0.100.2-lp150.2.6.1
Comment 6 Swamp Workflow Management 2018-10-25 16:09:31 UTC
SUSE-SU-2018:3436-1: An update that fixes four vulnerabilities is now available.

Category: security (moderate)
Bug References: 1103040,1104457,1110723
CVE References: CVE-2018-14680,CVE-2018-14681,CVE-2018-14682,CVE-2018-15378
Sources used:
SUSE OpenStack Cloud 7 (src):    clamav-0.100.2-33.18.1
SUSE Linux Enterprise Server for SAP 12-SP2 (src):    clamav-0.100.2-33.18.1
SUSE Linux Enterprise Server 12-SP3 (src):    clamav-0.100.2-33.18.1
SUSE Linux Enterprise Server 12-SP2-LTSS (src):    clamav-0.100.2-33.18.1
SUSE Linux Enterprise Server 12-SP2-BCL (src):    clamav-0.100.2-33.18.1
SUSE Linux Enterprise Server 12-SP1-LTSS (src):    clamav-0.100.2-33.18.1
SUSE Linux Enterprise Server 12-LTSS (src):    clamav-0.100.2-33.18.1
SUSE Linux Enterprise Desktop 12-SP3 (src):    clamav-0.100.2-33.18.1
SUSE Enterprise Storage 4 (src):    clamav-0.100.2-33.18.1
Comment 7 Swamp Workflow Management 2018-10-25 16:14:35 UTC
SUSE-SU-2018:3441-1: An update that fixes four vulnerabilities is now available.

Category: security (moderate)
Bug References: 1103040,1104457,1110723
CVE References: CVE-2018-14680,CVE-2018-14681,CVE-2018-14682,CVE-2018-15378
Sources used:
SUSE Linux Enterprise Server 11-SP4 (src):    clamav-0.100.2-0.20.18.1
SUSE Linux Enterprise Server 11-SP3-LTSS (src):    clamav-0.100.2-0.20.18.1
SUSE Linux Enterprise Point of Sale 11-SP3 (src):    clamav-0.100.2-0.20.18.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    clamav-0.100.2-0.20.18.1
SUSE Linux Enterprise Debuginfo 11-SP3 (src):    clamav-0.100.2-0.20.18.1
Comment 8 Swamp Workflow Management 2018-10-26 22:16:14 UTC
openSUSE-SU-2018:3505-1: An update that fixes four vulnerabilities is now available.

Category: security (moderate)
Bug References: 1103040,1104457,1110723
CVE References: CVE-2018-14680,CVE-2018-14681,CVE-2018-14682,CVE-2018-15378
Sources used:
openSUSE Leap 42.3 (src):    clamav-0.100.2-32.1
Comment 9 Swamp Workflow Management 2019-04-27 22:40:05 UTC
SUSE-SU-2018:3436-2: An update that fixes four vulnerabilities is now available.

Category: security (moderate)
Bug References: 1103040,1104457,1110723
CVE References: CVE-2018-14680,CVE-2018-14681,CVE-2018-14682,CVE-2018-15378
Sources used:
SUSE Linux Enterprise Server for SAP 12-SP1 (src):    clamav-0.100.2-33.18.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 10 Alexandros Toptsoglou 2020-04-28 15:39:44 UTC
Done