CVE-2018-1000085 log

Source
Severity Medium
Remote Yes
Type Denial of service
Description
A heap-based out-of-bounds read has been found in the xar_hash_check function of the xar decoder of ClamAV before 0.99.4, leading to a denial of service.
Group Package Affected Fixed Severity Status Ticket
AVG-602 clamav 0.99.3-1 0.99.4-1 Critical Fixed
Date Advisory Group Package Severity Description
18 Mar 2018 ASA-201803-14 AVG-602 clamav Critical multiple issues
References
http://www.openwall.com/lists/oss-security/2017/09/29/4
https://github.com/Cisco-Talos/clamav-devel/commit/d96a6b8bcc7439fa7e3876207aa0a8e79c8451b6
https://bugzilla.clamav.net/show_bug.cgi?id=11588