Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Mageia: 2019-0162 Moderate: ClamAV Denial Of Service Issues

mageia
Calendar Grey May 12, 2019
Dist Mageia Esm H88
Mageia 2020-0456 introduces revised ClamAV packages that tackle security issues and mitigate possible Denial of Service scenarios.
The updated packages fix security vulnerabilities: A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101....

Summary

The updated packages fix security vulnerabilities:
A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a lack of proper data handling mechanisms within the device buffer while indexing remaining file data on an affected device. An attacker could exploit this vulnerability by sending crafted PDF files to an affected device. A successful exploit could allow the attacker to cause a heap buffer out-of-bounds read condition, resulting in a crash that could result in a denial of service condition on an affected device. (CVE-2019-1787)
A vulnerability in the Object Linking & Embedding (OLE2) file scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service condi...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=24704

- https://ubuntu.com/security/notices/USN-3940-1

- https://www.cve.org/CVERecord?id=CVE-2019-1787

- https://www.cve.org/CVERecord?id=CVE-2019-1788

- https://www.cve.org/CVERecord?id=CVE-2019-1789

Resolution

SRPMS

- 6/core/clamav-0.100.3-1.mga6

Publication date: 12 May 2019
URL: https://advisories.mageia.org/MGASA-2019-0162.html
Type: security
CVE: CVE-2019-1787, CVE-2019-1788, CVE-2019-1789

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here