PT-2019-15256 · Cisco+2 · Clamav+2

Publicado

2019-03-28

·

Atualizado

2024-06-15

·

CVE-2019-1798

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ClamAV Software versions 0.101.1 and prior
Description A vulnerability in the Portable Executable (PE) file scanning functionality could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The issue is due to a lack of proper input and validation checking mechanisms for PE files sent to an affected device. An attacker could exploit this by sending malformed PE files to the device, potentially causing an out-of-bounds read condition and resulting in a crash that leads to a denial of service condition.
Recommendations For ClamAV Software versions 0.101.1 and prior, update to a version later than 0.101.1 to resolve the issue. As a temporary workaround, consider restricting the handling of PE files by the affected software until a patch is available.

Exploit

Correção

DoS

RCE

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-1538
CVE-2019-1798
OPENSUSE-SU-2020:2268-1
OPENSUSE-SU-2020:2276-1
OPENSUSE-SU-2020_2268-1
OPENSUSE-SU-2020_2276-1
OPENSUSE-SU-2024:10685-1
SUSE-SU-2020:3790-1

Produtos afetados

Alt Linux
Clamav
Suse