CVE-2018-15378: Canonical Ubuntu Linux

Medium severity, CVSS 5.5. EPSS: 1.3% chance of exploitation in the next 30 days.

A vulnerability in ClamAV versions prior to 0.100.2 could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to an error related to the MEW unpacker within the "unmew11()" function (libclamav/mew.c), which can be exploited to trigger an invalid read memory access via a specially crafted EXE file.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only
  • Clamav Clamav: before 0.100.2 (fixed in 0.100.2)
  • Debian Debian Linux: version 8.0 only

Published 2018-10-15. Last modified 2026-06-17.