Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.902189
Categoría:Denial of Service
Título:ClamAV 'cli_pdf()' and 'cli_scanicon()' Denial of Service Vulnerabilities (Win
Resumen:This host has ClamAV installed, and is prone to multiple Denial of Service; vulnerabilities.
Descripción:Summary:
This host has ClamAV installed, and is prone to multiple Denial of Service
vulnerabilities.

Vulnerability Insight:
The flaws are due to:

- Errors exist within the 'cli_pdf()' function in 'libclamav/pdf.c' when
processing certain 'PDF' files. This can be exploited to cause a crash.

- Errors exist within the 'parseicon()' function in 'libclamav/pe_icons.c'
when processing 'PE' icons. This can be exploited to trigger an out-of-bounds
access when reading data and potentially cause a crash.

Vulnerability Impact:
Successful exploitation will allow attackers to cause a denial of service.

Affected Software/OS:
ClamAV version prior to 0.96.1 (1.0.26) on Windows.

Solution:
Upgrade to ClamAV 0.96.1 or later.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:P

Referencia Cruzada: BugTraq ID: 40318
BugTraq ID: 40317
Common Vulnerability Exposure (CVE) ID: CVE-2010-1639
http://www.securityfocus.com/bid/40317
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055771.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055777.html
http://www.mandriva.com/security/advisories?name=MDVSA-2010:110
http://www.securitytracker.com/id?1024017
http://secunia.com/advisories/39895
http://secunia.com/advisories/43752
SuSE Security Announcement: SUSE-SR:2010:014 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html
http://www.vupen.com/english/advisories/2010/1214
XForce ISS Database: clamav-clipdf-dos(58824)
https://exchange.xforce.ibmcloud.com/vulnerabilities/58824
Common Vulnerability Exposure (CVE) ID: CVE-2010-1640
http://www.securityfocus.com/bid/40318
http://www.openwall.com/lists/oss-security/2010/05/21/7
XForce ISS Database: clamav-parseicon-dos(58825)
https://exchange.xforce.ibmcloud.com/vulnerabilities/58825
CopyrightCopyright (C) 2010 Greenbone Networks GmbH

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.