clamav: Multiple vulnerabilities (CVE-2018-15378, CVE-2018-14680, CVE-2018-14681, CVE-2018-14682)
Fixes for the following ClamAV vulnerabilities:¶
CVE-2018-15378: Vulnerability in ClamAV's MEW unpacking feature that could allow an unauthenticated,
remote attacker to cause a denial of service (DoS) condition on an affected device.
Fixes for the following vulnerabilities in bundled third-party libraries:¶
CVE-2018-14680: An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. It does not reject blank CHM filenames.
CVE-2018-14681: An issue was discovered in kwajd_read_headers in mspack/kwajd.c in libmspack before 0.7alpha. Bad KWAJ file header extensions could cause a one or two byte overwrite.
CVE-2018-14682: An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER macro for CHM decompression.
Fixed In Version:¶