Lucene search

K
ubuntucveUbuntu.comUB:CVE-2010-3434
HistorySep 30, 2010 - 12:00 a.m.

CVE-2010-3434

2010-09-3000:00:00
ubuntu.com
ubuntu.com
12

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

0.038 Low

EPSS

Percentile

92.0%

Buffer overflow in the find_stream_bounds function in pdf.c in libclamav in
ClamAV before 0.96.3 allows remote attackers to cause a denial of service
(application crash) or possibly execute arbitrary code via a crafted PDF
document. NOTE: some of these details are obtained from third party
information.

Bugs

Notes

Author Note
mdeslaur pdf library in clamav < 0.96.2 is completely different and doesn’t seem affected by the reproducer.

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

0.038 Low

EPSS

Percentile

92.0%