libclamav/message.c in ClamAV 0.99.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted e-mail message.
[
{
"id": "CVE-2017-6418-8e38158c",
"source": "https://github.com/cisco-talos/clamav/commit/586a5180287262070637c8943f2f7efd652e4a2c",
"deprecated": false,
"signature_version": "v1",
"target": {
"function": "messageFindArgument",
"file": "libclamav/message.c"
},
"digest": {
"function_hash": "8411924773331322618058653145915899983",
"length": 1064.0
},
"signature_type": "Function"
},
{
"id": "CVE-2017-6418-9cdcd390",
"source": "https://github.com/cisco-talos/clamav/commit/586a5180287262070637c8943f2f7efd652e4a2c",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "libclamav/message.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"81931090794367225593898439055161933938",
"167980574969179440687084582597496753902",
"55448340559487015224720964135014407383",
"38589169098278769608933629461838857826",
"172726005500348110301429670464002460835",
"36647451159828582513517242816843091264",
"192655131298326637061029023059490605418",
"163648590445410673071781345614646550543",
"276871485249595305150905337292995692585"
]
},
"signature_type": "Line"
},
{
"id": "CVE-2017-6418-ddca6c31",
"source": "https://github.com/cisco-talos/clamav/commit/586a5180287262070637c8943f2f7efd652e4a2c",
"deprecated": false,
"signature_version": "v1",
"target": {
"function": "messageAddArgument",
"file": "libclamav/message.c"
},
"digest": {
"function_hash": "203584271026814593334015189844539459788",
"length": 1512.0
},
"signature_type": "Function"
}
]