CVE-2018-0202 log

Source
Severity Critical
Remote Yes
Type Arbitrary code execution
Description
A heap overflow has been discovered in ClamAv before 0.99.4 in pdf_parse_string possibly leading to arbitrary code execution by inspecting a specially crafted PDF file.
Group Package Affected Fixed Severity Status Ticket
AVG-602 clamav 0.99.3-1 0.99.4-1 Critical Fixed
Date Advisory Group Package Severity Description
18 Mar 2018 ASA-201803-14 AVG-602 clamav Critical multiple issues
References
https://bugzilla.clamav.net/show_bug.cgi?id=11973
https://bugzilla.clamav.net/show_bug.cgi?id=11980
https://github.com/Cisco-Talos/clamav-devel/commit/87aaa10b29476958f5bf54b6119a133069f944fc
https://github.com/Cisco-Talos/clamav-devel/commit/700ed96af56077cb1a9bff7b91d21db112f6465d
https://github.com/Cisco-Talos/clamav-devel/commit/0df2fedf2805e574512c486b32a0fff4ed394560
https://github.com/Cisco-Talos/clamav-devel/commit/495fce917445063d519f14b0009cee025f817bc3
https://github.com/Cisco-Talos/clamav-devel/commit/99eadf7a9ad351210165312362d1f32b77c6f857