Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-20505

Опубликовано: 04 сент. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 4

Описание

A vulnerability in the PDF parsing module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2.x versions, 1.0.6 and prior versions, all 0.105.x versions, all 0.104.x versions, and 0.103.11 and all prior versions could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to an out of bounds read. An attacker could exploit this vulnerability by submitting a crafted PDF file to be scanned by ClamAV on an affected device. An exploit could allow the attacker to terminate the scanning process.

РелизСтатусПримечание
devel

released

1.3.1+dfsg-5ubuntu2
esm-infra-legacy/trusty

needed

esm-infra/bionic

released

0.103.12+dfsg-0ubuntu0.18.04.1+esm1
esm-infra/focal

released

0.103.12+dfsg-0ubuntu0.20.04.1
esm-infra/xenial

released

0.103.12+dfsg-0ubuntu0.16.04.1+esm1
focal

released

0.103.12+dfsg-0ubuntu0.20.04.1
jammy

released

0.103.12+dfsg-0ubuntu0.22.04.1
noble

released

1.0.7+dfsg-0ubuntu0.24.04.1
oracular

released

1.3.1+dfsg-5ubuntu2
plucky

released

1.3.1+dfsg-5ubuntu2

Показывать по

EPSS

Процентиль: 75%
0.0089
Низкий

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4
nvd
больше 1 года назад

A vulnerability in the PDF parsing module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2.x versions, 1.0.6 and prior versions, all 0.105.x versions, all 0.104.x versions, and 0.103.11 and all prior versions could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to an out of bounds read. An attacker could exploit this vulnerability by submitting a crafted PDF file to be scanned by ClamAV on an affected device. An exploit could allow the attacker to terminate the scanning process.

CVSS3: 7.5
msrc
около 1 года назад

ClamAV Memory Handling DoS

CVSS3: 4
debian
больше 1 года назад

A vulnerability in the PDF parsing module of Clam AntiVirus (ClamAV) v ...

CVSS3: 4
github
больше 1 года назад

A vulnerability in the PDF parsing module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2.x versions, 1.0.6 and prior versions, all 0.105.x versions, all 0.104.x versions, and 0.103.11 and all prior versions could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to an out of bounds read. An attacker could exploit this vulnerability by submitting a crafted PDF file to be scanned by ClamAV on an affected device. An exploit could allow the attacker to terminate the scanning process.

CVSS3: 7.5
fstec
больше 1 года назад

Уязвимость компонента анализа pdf-файлов пакета антивирусных программ ClamAV, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 75%
0.0089
Низкий

4 Medium

CVSS3