clamscan in ClamAV before 0.99.4 contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation checking mechanisms when handling Portable Document Format (.pdf) files sent to an affected device. An unauthenticated, remote attacker could exploit this vulnerability by sending a crafted .pdf file to an affected device. This action could cause an out-of-bounds read when ClamAV scans the malicious file, allowing the attacker to cause a DoS condition. This concerns pdf_parse_array and pdf_parse_string in libclamav/pdfng.c. Cisco Bug IDs: CSCvh91380, CSCvh91400.
History

Mon, 02 Dec 2024 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published: 2018-03-27T09:00:00

Updated: 2024-12-02T20:55:52.456Z

Reserved: 2017-11-27T00:00:00

Link: CVE-2018-0202

cve-icon Vulnrichment

Updated: 2024-08-05T03:14:16.872Z

cve-icon NVD

Status : Modified

Published: 2018-03-27T09:29:00.387

Modified: 2024-11-21T03:37:43.290

Link: CVE-2018-0202

cve-icon Redhat

No data.