PT-2019-15253 · Cisco+2 · Clamav+2

Published

2019-03-28

·

Updated

2024-06-15

·

CVE-2019-1786

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ClamAV Software versions 0.101.1 through 0.101.0
Description A vulnerability in the Portable Document Format (PDF) scanning functionality could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The issue is due to a lack of proper data handling mechanisms within the device buffer while indexing remaining file data. An attacker could exploit this by sending crafted PDF files to an affected device, potentially causing an out-of-bounds read condition and resulting in a crash that leads to a denial of service condition.
Recommendations For ClamAV Software versions 0.101.1 and 0.101.0, consider disabling the PDF scanning functionality until a patch is available to prevent potential exploitation. Restrict access to the device to minimize the risk of receiving crafted PDF files.

Fix

DoS

RCE

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1538
CVE-2019-1786
OPENSUSE-SU-2020:2268-1
OPENSUSE-SU-2020:2276-1
OPENSUSE-SU-2020_2268-1
OPENSUSE-SU-2020_2276-1
OPENSUSE-SU-2024:10685-1
SUSE-SU-2020:3790-1

Affected Products

Alt Linux
Clamav
Suse