CVE-2021-1404
Summary
| CVE | CVE-2021-1404 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-08 05:15:00 UTC |
| Updated | 2022-08-05 17:18:00 UTC |
| Description | A vulnerability in the PDF parsing module in Clam AntiVirus (ClamAV) Software versions 0.103.0 and 0.103.1 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper buffer size tracking that may result in a heap buffer over-read. An attacker could exploit this vulnerability by sending a crafted PDF file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to crash, resulting in a denial of service condition. |
Risk And Classification
Problem Types: CWE-125
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ClamAV® blog: ClamAV 0.103.2 security patch release | CISCO | blog.clamav.net | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 174899 SUSE Enterprise Linux Security Update for clamav (SUSE-SU-2021:1174-1)
- 174903 SUSE Enterprise Linux Security Update for clamav (SUSE-SU-2021:1190-1)
- 174911 SUSE Enterprise Linux Security Update for clamav (SUSE-SU-2021:1189-1)
- 179824 Debian Security Update for clamav (CVE-2021-1404)
- 198334 Ubuntu Security Notification for ClamAV vulnerabilities (USN-4918-1)
- 375524 ClamAV Multiple Vulnerability
- 500100 Alpine Linux Security Update for clamav
- 503825 Alpine Linux Security Update for clamav
- 690182 Free Berkeley Software Distribution (FreeBSD) Security Update for clamav (9ae2c00f-97d0-11eb-8cd6-080027f515ea)
- 750265 OpenSUSE Security Update for clamav (openSUSE-SU-2021:0555-1)
- 900102 CBL-Mariner Linux Security Update for clamav 0.103.0
- 903084 Common Base Linux Mariner (CBL-Mariner) Security Update for clamav (4077)