CVE-2010-4260
published 2010-12-07CVE-2010-4260: Multiple unspecified vulnerabilities in pdf.c in libclamav in ClamAV before 0.96.5 allow remote attackers to cause a denial of service (application crash) or…
PriorityP428medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
4.90%
91.2th percentile
Multiple unspecified vulnerabilities in pdf.c in libclamav in ClamAV before 0.96.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document, aka (1) "bb #2358" and (2) "bb #2396."
Affected
95 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| clamav | clamav | <= 0.96.4 | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
ClamAV vulnerabilities
vendor_ubuntu·2010-12-10·CVSS 5.0
CVE-2010-4479 [MEDIUM] ClamAV vulnerabilities
Title: ClamAV vulnerabilities
Arkadiusz Miskiewicz and others discovered that the PDF processing
code in libclamav improperly validated input. This could allow a
remote attacker to craft a PDF document that could crash clamav or
possibly execute arbitrary code. (CVE-2010-4260, CVE-2010-4479)
It was discovered that an off-by-one error in the icon_cb function
in pe_icons.c in libclamav could allow an attacker to corrupt
memory, causing clamav to crash or possibly execute arbitrary code.
(CVE-2010-4261)
In the default installation, attackers would be isolated by the
clamav AppArmor profile.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2010-4479: clamav - Unspecified vulnerability in pdf.c in libclamav in ClamAV before 0.96.5 allows r...
vendor_debian·2010·CVSS 5.0
CVE-2010-4479 [MEDIUM] CVE-2010-4479: clamav - Unspecified vulnerability in pdf.c in libclamav in ClamAV before 0.96.5 allows r...
Unspecified vulnerability in pdf.c in libclamav in ClamAV before 0.96.5 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document, aka "bb #2380," a different vulnerability than CVE-2010-4260.
Scope: local
bookworm: resolved (fixed in 0.96.5+dfsg-1)
bullseye: resolved (fixed in 0.96.5+dfsg-1)
forky: resolved (fixed in 0.96.5+dfsg-1)
sid: resolved (fixed in 0.96.5+dfsg-1)
trixie: resolved (fixed in 0.96.5+dfsg-1)
Debian
CVE-2010-4260: clamav - Multiple unspecified vulnerabilities in pdf.c in libclamav in ClamAV before 0.96...
vendor_debian·2010·CVSS 5.0
CVE-2010-4260 [MEDIUM] CVE-2010-4260: clamav - Multiple unspecified vulnerabilities in pdf.c in libclamav in ClamAV before 0.96...
Multiple unspecified vulnerabilities in pdf.c in libclamav in ClamAV before 0.96.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document, aka (1) "bb #2358" and (2) "bb #2396."
Scope: local
bookworm: resolved (fixed in 0.96.5+dfsg-1)
bullseye: resolved (fixed in 0.96.5+dfsg-1)
forky: resolved (fixed in 0.96.5+dfsg-1)
sid: resolved (fixed in 0.96.5+dfsg-1)
trixie: resolved (fixed in 0.96.5+dfsg-1)
GHSA
GHSA-wxr2-5mq6-gvcq: Unspecified vulnerability in pdf
ghsa_unreviewed·2022-05-17·CVSS 5.0
CVE-2010-4479 [MEDIUM] GHSA-wxr2-5mq6-gvcq: Unspecified vulnerability in pdf
Unspecified vulnerability in pdf.c in libclamav in ClamAV before 0.96.5 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document, aka "bb #2380," a different vulnerability than CVE-2010-4260.
GHSA
GHSA-2c2w-ghqr-g6hj: Multiple unspecified vulnerabilities in pdf
ghsa_unreviewed·2022-05-17
CVE-2010-4260 [MEDIUM] GHSA-2c2w-ghqr-g6hj: Multiple unspecified vulnerabilities in pdf
Multiple unspecified vulnerabilities in pdf.c in libclamav in ClamAV before 0.96.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document, aka (1) "bb #2358" and (2) "bb #2396."
OSV
CVE-2010-4479: Unspecified vulnerability in pdf
osv·2010-12-07·CVSS 5.0
CVE-2010-4479 [MEDIUM] CVE-2010-4479: Unspecified vulnerability in pdf
Unspecified vulnerability in pdf.c in libclamav in ClamAV before 0.96.5 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document, aka "bb #2380," a different vulnerability than CVE-2010-4260.
OSV
CVE-2010-4260: Multiple unspecified vulnerabilities in pdf
osv·2010-12-07·CVSS 5.0
CVE-2010-4260 [MEDIUM] CVE-2010-4260: Multiple unspecified vulnerabilities in pdf
Multiple unspecified vulnerabilities in pdf.c in libclamav in ClamAV before 0.96.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document, aka (1) "bb #2358" and (2) "bb #2396."
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-4260 CVE-2010-4261 CVE-2010-4479 clamav: multiple flaws corrected in 0.96.5 [fedora-all]
bugzilla·2010-12-03·CVSS 5.0
CVE-2010-4260 [MEDIUM] CVE-2010-4260 CVE-2010-4261 CVE-2010-4479 clamav: multiple flaws corrected in 0.96.5 [fedora-all]
CVE-2010-4260 CVE-2010-4261 CVE-2010-4479 clamav: multiple flaws corrected in 0.96.5 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=659861
Please note: this
Bugzilla
CVE-2010-4260 CVE-2010-4261 CVE-2010-4479 clamav: multiple flaws corrected in 0.96.5
bugzilla·2010-12-03·CVSS 5.0
CVE-2010-4260 [MEDIUM] CVE-2010-4260 CVE-2010-4261 CVE-2010-4479 clamav: multiple flaws corrected in 0.96.5
CVE-2010-4260 CVE-2010-4261 CVE-2010-4479 clamav: multiple flaws corrected in 0.96.5
Two flaws were reported to have been corrected in ClamAV 0.96.5 [1]:
1) Multiple errors within the processing of PDF files can be exploited to e.g. cause a crash. (CVE-2010-4260)
2) An off-by-one error within the "icon_cb()" function can be exploited to cause a memory corruption. (CVE-2010-4261)
Current Fedora version of ClamAV is 0.96.4 and is vulnerable to these issues.
[1] http://secunia.com/advisories/42426/
Discussion:
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-4479 to
the following vulnerability:
Name: CVE-2010-4479
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4479
Assigned: 20101206
Reference: MLIST:[oss-security] 20101203 Re: clamav 0.96.5 released
R
http://git.clamav.net/gitweb?p=clamav-devel.git%3Ba=blob_plain%3Bf=ChangeLog%3Bhb=masterhttp://lists.apple.com/archives/security-announce/2011/Mar/msg00006.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/051905.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052401.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.htmlhttp://openwall.com/lists/oss-security/2010/12/03/1http://openwall.com/lists/oss-security/2010/12/03/3http://openwall.com/lists/oss-security/2010/12/03/6http://secunia.com/advisories/42426http://secunia.com/advisories/42523http://secunia.com/advisories/42555http://secunia.com/advisories/42720http://support.apple.com/kb/HT4581http://www.mandriva.com/security/advisories?name=MDVSA-2010:249http://www.securityfocus.com/bid/45152http://www.securitytracker.com/id?1024818http://www.ubuntu.com/usn/USN-1031-1http://www.vupen.com/english/advisories/2010/3135http://www.vupen.com/english/advisories/2010/3137http://www.vupen.com/english/advisories/2010/3185http://xorl.wordpress.com/2010/12/06/cve-2010-4260-clamav-multiple-pdf-vulnerabilities/https://bugzilla.redhat.com/show_bug.cgi?id=659861https://wwws.clamav.net/bugzilla/show_bug.cgi?id=2358https://wwws.clamav.net/bugzilla/show_bug.cgi?id=2396http://git.clamav.net/gitweb?p=clamav-devel.git%3Ba=blob_plain%3Bf=ChangeLog%3Bhb=masterhttp://lists.apple.com/archives/security-announce/2011/Mar/msg00006.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/051905.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052401.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.htmlhttp://openwall.com/lists/oss-security/2010/12/03/1http://openwall.com/lists/oss-security/2010/12/03/3http://openwall.com/lists/oss-security/2010/12/03/6http://secunia.com/advisories/42426http://secunia.com/advisories/42523http://secunia.com/advisories/42555http://secunia.com/advisories/42720http://support.apple.com/kb/HT4581http://www.mandriva.com/security/advisories?name=MDVSA-2010:249http://www.securityfocus.com/bid/45152http://www.securitytracker.com/id?1024818http://www.ubuntu.com/usn/USN-1031-1http://www.vupen.com/english/advisories/2010/3135http://www.vupen.com/english/advisories/2010/3137http://www.vupen.com/english/advisories/2010/3185http://xorl.wordpress.com/2010/12/06/cve-2010-4260-clamav-multiple-pdf-vulnerabilities/https://bugzilla.redhat.com/show_bug.cgi?id=659861https://wwws.clamav.net/bugzilla/show_bug.cgi?id=2358https://wwws.clamav.net/bugzilla/show_bug.cgi?id=2396
2010-12-07
Published