CVE-2019-12625
05.11.2019, 19:15
ClamAV versions prior to 0.101.3 are susceptible to a zip bomb vulnerability where an unauthenticated attacker can cause a denial of service condition by sending crafted messages to an affected system.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| clamav | clamav | 𝑥 < 0.101.3 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| clamav |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| clamav-devel |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| clamav-docs-html |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| clamav-milter |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| libclamav12 |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| libclamav7 |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| libclamav9 |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| libclammspack0 |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| libfreshclam2 |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| libfreshclam3 |
|
Common Weakness Enumeration
- CWE-400 - Uncontrolled Resource ConsumptionThe software does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
- CWE-404 - Improper Resource Shutdown or ReleaseThe program does not release or incorrectly releases a resource before it is made available for re-use.
References