PT-2021-2686 · Clamav+5 · Clamav+5

Published

2021-04-08

·

Updated

2026-02-06

·

CVE-2021-1405

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Clam AntiVirus (ClamAV) Software versions 0.103.1 and all prior versions Clam AntiVirus (ClamAV) Software versions 0.103.0 and 0.103.1
Description A vulnerability in the email parsing module and PDF parsing module in Clam AntiVirus (ClamAV) Software could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper variable initialization and buffer size tracking that may result in a NULL pointer read or heap buffer over-read. An attacker could exploit this vulnerability by sending a crafted email or PDF file to an affected device, allowing the attacker to cause the ClamAV scanning process to crash, resulting in a denial of service condition.
Recommendations For Clam AntiVirus (ClamAV) Software versions 0.103.1 and all prior versions, update to a version that fixes the improper variable initialization issue. For Clam AntiVirus (ClamAV) Software versions 0.103.0 and 0.103.1, update to a version that fixes the improper buffer size tracking issue. As a temporary workaround, consider restricting the input to the email and PDF parsing modules to minimize the risk of exploitation.

Fix

DoS

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1627
ALT-PU-2021-1635
ALT-PU-2022-1152
BDU:2021-02217
CLEANSTART-2026-LA13761
CLEANSTART-2026-NJ87139
CLEANSTART-2026-TC95380
CLEANSTART-2026-WX01708
CVE-2021-1405
DLA-2626-1
MGASA-2021-0194
OPENSUSE-SU-2021:0555-1
OPENSUSE-SU-2021_0555-1
OPENSUSE-SU-2024:10685-1
SUSE-SU-2021:1174-1
SUSE-SU-2021:1189-1
SUSE-SU-2021:1190-1
SUSE-SU-2021:14692-1
SUSE-SU-2021_14692-1
USN-4918-1
USN-4918-2
USN-4918-3

Affected Products

Alt Linux
Clam Antivirus
Clamav
Linuxmint
Suse
Ubuntu