Ubuntu – ClamAV: PUA.Win.Exploit.CVE_2012_0110 FOUND (/usr/share/mime/mime.cache)

antivirusclamavmalwareSecurity

I recently scanned my system with (I am running the latest version of ClamAV and my definitions are up-to-date):

sudo clamscan -r --detect-pua --infected --bell /

And this one was of the results:

/usr/share/mime/mime.cache: PUA.Win.Exploit.CVE_2012_0110 FOUND

I have not seen anything like this before, so what is this, is this anything to worry about, and should I do anything about it? Also, what is the purpose of the location that it was found in?

Additional Information:

You can download the mime.cache file here: https://www.dropbox.com/s/58sxjv48ye4p6au/mime.cache?dl=0

And I appear to have found what this CVE_2012_0110 is, as it is one of the vulnerabilities listed on this page.

I have scanned the file on VirusTotal, and although the only thing which detected something bad was in the Additional information section at the bottom, I don't necessarily trust that all is well because if something was say injected into that file or something, then perhaps it would be more heuristics that would detect it rather than matching MD5 sums. Here is the report: report


OS Information:

Description:    Ubuntu 14.10
Release:    14.10

Best Answer

This is probably just a false positive. /usr/share/mime/mime.cache is a generated file of all known mime types on your system. It's not an executable.

Virus scanners detect malicious software by sets of known fingerprints (hashes). This model leads to some false positives, inevitably. Perhaps it's a coincedence a known Windows virus matches the fingerprint as found on a Linux system, perhaps it's because the fingerprint just matches a certain MIME type pattern that will match inevitably on any Linux system...

For now, I wouldn't worry about it, but just contact the ClamAV team to ask whether this is a known issue with them already.

Also make sure to stay updated with the most recent ClamAV fingerprints (freshclam).