A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a lack of proper data handling mechanisms within the device buffer while indexing remaining file data on an affected device. An attacker could exploit this vulnerability by sending crafted PDF files to an affected device. A successful exploit could allow the attacker to cause a heap buffer out-of-bounds read condition, resulting in a crash that could result in a denial of service condition on an affected device.
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00062.html
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00064.html
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=12181
https://lists.debian.org/debian-lts-announce/2019/04/msg00019.html
Source: MITRE
Published: 2019-04-08
Updated: 2019-10-09
Type: CWE-125
Base Score: 4.3
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P
Impact Score: 2.9
Exploitability Score: 8.6
Severity: MEDIUM
Base Score: 5.5
Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Impact Score: 3.6
Exploitability Score: 1.8
Severity: MEDIUM
OR
cpe:2.3:a:clamav:clamav:*:*:*:*:*:*:*:* versions up to 0.101.1 (inclusive)
OR
OR
ID | Name | Product | Family | Severity |
---|---|---|---|---|
145338 | openSUSE Security Update : clamav (openSUSE-2020-2268) | Nessus | SuSE Local Security Checks | high |
145307 | openSUSE Security Update : clamav (openSUSE-2020-2276) | Nessus | SuSE Local Security Checks | high |
144237 | SUSE SLED15 / SLES15 Security Update : clamav (SUSE-SU-2020:3790-1) | Nessus | SuSE Local Security Checks | high |
125295 | Amazon Linux AMI : clamav (ALAS-2019-1213) | Nessus | Amazon Linux Local Security Checks | medium |
124217 | Debian DLA-1759-1 : clamav security update | Nessus | Debian Local Security Checks | medium |
124103 | openSUSE Security Update : clamav (openSUSE-2019-1210) | Nessus | SuSE Local Security Checks | medium |
124101 | openSUSE Security Update : clamav (openSUSE-2019-1208) | Nessus | SuSE Local Security Checks | medium |
123984 | GLSA-201904-12 : ClamAV: Multiple vulnerabilities | Nessus | Gentoo Local Security Checks | medium |
123972 | SUSE SLES11 Security Update : clamav (SUSE-SU-2019:14015-1) | Nessus | SuSE Local Security Checks | medium |
123932 | Ubuntu 14.04 LTS / 16.04 LTS / 18.04 LTS / 18.10 : clamav vulnerabilities (USN-3940-1) | Nessus | Ubuntu Local Security Checks | medium |
123923 | SUSE SLED12 / SLES12 Security Update : clamav (SUSE-SU-2019:0897-1) | Nessus | SuSE Local Security Checks | medium |
123809 | FreeBSD : clamav -- multiple vulnerabilities (84ce26c3-5769-11e9-abd6-001b217b3468) | Nessus | FreeBSD Local Security Checks | medium |
123749 | SUSE SLED15 / SLES15 Security Update : clamav (SUSE-SU-2019:0861-1) | Nessus | SuSE Local Security Checks | medium |