PT-2019-15253 · Cisco+2 · Clamav+2
Published
2019-03-28
·
Updated
2024-06-15
·
CVE-2019-1786
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
ClamAV Software versions 0.101.1 through 0.101.0
Description
A vulnerability in the Portable Document Format (PDF) scanning functionality could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The issue is due to a lack of proper data handling mechanisms within the device buffer while indexing remaining file data. An attacker could exploit this by sending crafted PDF files to an affected device, potentially causing an out-of-bounds read condition and resulting in a crash that leads to a denial of service condition.
Recommendations
For ClamAV Software versions 0.101.1 and 0.101.0, consider disabling the PDF scanning functionality until a patch is available to prevent potential exploitation. Restrict access to the device to minimize the risk of receiving crafted PDF files.
Fix
DoS
RCE
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Clamav
Suse