Medium severity5.5NVD Advisory· Published Aug 7, 2017· Updated May 13, 2026
CVE-2017-6420
CVE-2017-6420
Description
The wwunpack function in libclamav/wwunpack.c in ClamAV 0.99.2 allows remote attackers to cause a denial of service (use-after-free) via a crafted PE file with WWPack compression.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/vrtadmin/clamav-devel/commit/dfc00cd3301a42b571454b51a6102eecf58407bcnvdIssue TrackingPatchThird Party Advisory
- github.com/varsleak/varsleak-vul/blob/master/clamav-vul/use-after-free/clamav-use-after-free-pe.mdnvdThird Party Advisory
- bugzilla.clamav.net/show_bug.cginvdPermissions Required
- security.gentoo.org/glsa/201804-16nvd
News mentions
0No linked articles in our index yet.