3.3
CVSSv3

CVE-2018-0361

Published: 16/07/2018 Updated: 26/04/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 3.3 | Impact Score: 1.4 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

ClamAV prior to 0.100.1 lacks a PDF object length check, resulting in an unreasonably long time to parse a relatively small file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

clamav clamav

debian debian linux 8.0

Vendor Advisories

ClamAV could be made to hang if it opened a specially crafted file ...
ClamAV could be made to hang if it opened a specially crafted file ...
USN-3722-1 introduced a regression in ClamAV ...
USN-3722-1 introduced a regression in ClamAV ...
USN-3722-1 introduced a regression in ClamAV ...
USN-3722-1 introduced a regression in ClamAV ...