CVE-2019-15961
Summary
| CVE | CVE-2019-15961 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-15 19:15:00 UTC |
| Updated | 2022-10-19 18:54:00 UTC |
| Description | A vulnerability in the email parsing module Clam AntiVirus (ClamAV) Software versions 0.102.0, 0.101.4 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to inefficient MIME parsing routines that result in extremely long scan times of specially formatted email files. An attacker could exploit this vulnerability by sending a crafted email file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to scan the crafted email file indefinitely, resulting in a denial of service condition. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 2108-1] clamav security update |
MLIST |
lists.debian.org |
|
| ClamAV: Multiple vulnerabilities (GLSA 202003-46) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| Cisco Bug: CSCvr56010 - Opened to track: ClamAV for Cisco Email Security Appliance (ESA) Denial of Service Vulnerability |
CISCO |
quickview.cloudapps.cisco.com |
Third Party Advisory |
| USN-4230-2: ClamAV vulnerability | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
|
| Bug 12380 – MIME Denial of Service Vulnerability |
CISCO |
bugzilla.clamav.net |
Exploit, Issue Tracking, Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500096 Alpine Linux Security Update for clamav
- 503821 Alpine Linux Security Update for clamav
- 750483 OpenSUSE Security Update for clamav (openSUSE-SU-2020:2276-1)
- 750485 OpenSUSE Security Update for clamav (openSUSE-SU-2020:2268-1)
- 900004 CBL-Mariner Linux Security Update for clamav 0.101.2
- 903412 Common Base Linux Mariner (CBL-Mariner) Security Update for clamav (3169)