CVE-2018-0361: Clamav

Low severity, CVSS 3.3. EPSS: 1.6% chance of exploitation in the next 30 days.

ClamAV before 0.100.1 lacks a PDF object length check, resulting in an unreasonably long time to parse a relatively small file.

Affected products

  • Clamav Clamav: before 0.100.1 (fixed in 0.100.1)
  • Debian Debian Linux: version 8.0 only

Published 2018-07-16. Last modified 2026-06-17.