Lucene search

K
osvGoogleOSV:USN-4918-3
HistoryMay 03, 2021 - 10:20 p.m.

clamav regression

2021-05-0322:20:06
Google
osv.dev
5

7.5 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

73.2%

USN-4918-1 fixed vulnerabilities in ClamAV. The updated package could
fail to properly scan in some situations. This update fixes
the problem.

Original advisory details:

It was discovered that ClamAV incorrectly handled parsing Excel documents.
A remote attacker could possibly use this issue to cause ClamAV to hang,
resulting in a denial of service. (CVE-2021-1252)

It was discovered that ClamAV incorrectly handled parsing PDF documents. A
remote attacker could possibly use this issue to cause ClamAV to crash,
resulting in a denial of service. (CVE-2021-1404)

It was discovered that ClamAV incorrectly handled parsing email. A remote
attacker could possibly use this issue to cause ClamAV to crash, resulting
in a denial of service. (CVE-2021-1405)