CVE-2007-2029File Descriptor Leak in Anti-virus Clamav

CWE-3995 documents5 sources
Severity
7.8HIGHNVD
EPSS
1.2%
top 21.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 30
Latest updateMay 1

Description

File descriptor leak in the PDF handler in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service via a crafted PDF file.

CVSS vector

AV:N/AC:L/C:N/I:N/A:CExploitability: 10.0 | Impact: 6.9

Affected Packages2 packages

Debianclamav/clamav< 0.90.2-1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-5vxf-6gr7-mr6m: File descriptor leak in the PDF handler in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service via a crafted PDF file2022-05-01
OSV
CVE-2007-2029: File descriptor leak in the PDF handler in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service via a crafted PDF file2007-04-30
CVEList
CVE-2007-2029: File descriptor leak in the PDF handler in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service via a crafted PDF file2007-04-30

📋Vendor Advisories

1
Debian
CVE-2007-2029: clamav - File descriptor leak in the PDF handler in Clam AntiVirus (ClamAV) allows remote...2007
CVE-2007-2029 — File Descriptor Leak | cvebase