Off-by-one error in the parseicon function in libclamav/pe_icons.c in ClamAV 0.96 allows remote attackers to cause a denial of service (crash) via a crafted PE icon that triggers an out-of-bounds read, related to improper rounding during scaling.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2010-05-26T18:00:00

Updated: 2024-08-07T01:28:41.582Z

Reserved: 2010-04-29T00:00:00

Link: CVE-2010-1640

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2010-05-26T18:30:01.827

Modified: 2023-02-13T04:19:27.087

Link: CVE-2010-1640

cve-icon Redhat

Severity : Low

Publid Date: 2010-05-18T00:00:00Z

Links: CVE-2010-1640 - Bugzilla