The wwunpack function in libclamav/wwunpack.c in ClamAV 0.99.2 allows remote attackers to cause a denial of service (use-after-free) via a crafted PE file with WWPack compression.
{ "vanir_signatures": [ { "digest": { "length": 3832.0, "function_hash": "139298605883294768074466177189333198170" }, "target": { "function": "wwunpack", "file": "libclamav/wwunpack.c" }, "signature_type": "Function", "source": "https://github.com/cisco-talos/clamav/commit/dfc00cd3301a42b571454b51a6102eecf58407bc", "deprecated": false, "signature_version": "v1", "id": "CVE-2017-6420-8db5ad48" }, { "digest": { "line_hashes": [ "35527508808006729459757378903195264297", "136599601490254595440116583910458001390", "213343516002541788284701737169634229176", "38984029225980571671566102348353921465" ], "threshold": 0.9 }, "target": { "file": "libclamav/wwunpack.c" }, "signature_type": "Line", "source": "https://github.com/cisco-talos/clamav/commit/dfc00cd3301a42b571454b51a6102eecf58407bc", "deprecated": false, "signature_version": "v1", "id": "CVE-2017-6420-c120f9f5" } ] }