Ubuntu Security Notice USN-672-1 – Moritz Jodeit discovered that ClamAV did not correctly handle certain strings when examining a VBA project. If a remote attacker tricked ClamAV into processing a malicious VBA file, ClamAV would crash, leading to a denial of service.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/72043/USN-672-1.txt
Source: https://packetstormsecurity.com/files/72043/Ubuntu-Security-Notice-672-1.html