CVE-2010-4261
published 2010-12-07CVE-2010-4261: Off-by-one error in the icon_cb function in pe_icons.c in libclamav in ClamAV before 0.96.5 allows remote attackers to cause a denial of service (memory…
PriorityP334high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.77%
91.0th percentile
Off-by-one error in the icon_cb function in pe_icons.c in libclamav in ClamAV before 0.96.5 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors. NOTE: some of these details are obtained from third party information.
Affected
95 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| clamav | clamav | <= 0.96.4 | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7686-g7vr-w687: Off-by-one error in the icon_cb function in pe_icons
ghsa_unreviewed·2022-05-17
CVE-2010-4261 [HIGH] GHSA-7686-g7vr-w687: Off-by-one error in the icon_cb function in pe_icons
Off-by-one error in the icon_cb function in pe_icons.c in libclamav in ClamAV before 0.96.5 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors. NOTE: some of these details are obtained from third party information.
OSV
CVE-2010-4261: Off-by-one error in the icon_cb function in pe_icons
osv·2010-12-07·CVSS 7.5
CVE-2010-4261 [HIGH] CVE-2010-4261: Off-by-one error in the icon_cb function in pe_icons
Off-by-one error in the icon_cb function in pe_icons.c in libclamav in ClamAV before 0.96.5 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors. NOTE: some of these details are obtained from third party information.
Ubuntu
ClamAV vulnerabilities
vendor_ubuntu·2010-12-10·CVSS 5.0
CVE-2010-4479 [MEDIUM] ClamAV vulnerabilities
Title: ClamAV vulnerabilities
Arkadiusz Miskiewicz and others discovered that the PDF processing
code in libclamav improperly validated input. This could allow a
remote attacker to craft a PDF document that could crash clamav or
possibly execute arbitrary code. (CVE-2010-4260, CVE-2010-4479)
It was discovered that an off-by-one error in the icon_cb function
in pe_icons.c in libclamav could allow an attacker to corrupt
memory, causing clamav to crash or possibly execute arbitrary code.
(CVE-2010-4261)
In the default installation, attackers would be isolated by the
clamav AppArmor profile.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2010-4261: clamav - Off-by-one error in the icon_cb function in pe_icons.c in libclamav in ClamAV be...
vendor_debian·2010·CVSS 7.5
CVE-2010-4261 [HIGH] CVE-2010-4261: clamav - Off-by-one error in the icon_cb function in pe_icons.c in libclamav in ClamAV be...
Off-by-one error in the icon_cb function in pe_icons.c in libclamav in ClamAV before 0.96.5 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors. NOTE: some of these details are obtained from third party information.
Scope: local
bookworm: resolved (fixed in 0.96.5+dfsg-1)
bullseye: resolved (fixed in 0.96.5+dfsg-1)
forky: resolved (fixed in 0.96.5+dfsg-1)
sid: resolved (fixed in 0.96.5+dfsg-1)
trixie: resolved (fixed in 0.96.5+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-4260 CVE-2010-4261 CVE-2010-4479 clamav: multiple flaws corrected in 0.96.5 [fedora-all]
bugzilla·2010-12-03·CVSS 5.0
CVE-2010-4260 [MEDIUM] CVE-2010-4260 CVE-2010-4261 CVE-2010-4479 clamav: multiple flaws corrected in 0.96.5 [fedora-all]
CVE-2010-4260 CVE-2010-4261 CVE-2010-4479 clamav: multiple flaws corrected in 0.96.5 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=659861
Please note: this
Bugzilla
CVE-2010-4260 CVE-2010-4261 CVE-2010-4479 clamav: multiple flaws corrected in 0.96.5
bugzilla·2010-12-03·CVSS 5.0
CVE-2010-4260 [MEDIUM] CVE-2010-4260 CVE-2010-4261 CVE-2010-4479 clamav: multiple flaws corrected in 0.96.5
CVE-2010-4260 CVE-2010-4261 CVE-2010-4479 clamav: multiple flaws corrected in 0.96.5
Two flaws were reported to have been corrected in ClamAV 0.96.5 [1]:
1) Multiple errors within the processing of PDF files can be exploited to e.g. cause a crash. (CVE-2010-4260)
2) An off-by-one error within the "icon_cb()" function can be exploited to cause a memory corruption. (CVE-2010-4261)
Current Fedora version of ClamAV is 0.96.4 and is vulnerable to these issues.
[1] http://secunia.com/advisories/42426/
Discussion:
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-4479 to
the following vulnerability:
Name: CVE-2010-4479
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4479
Assigned: 20101206
Reference: MLIST:[oss-security] 20101203 Re: clamav 0.96.5 released
R
http://git.clamav.net/gitweb?p=clamav-devel.git%3Ba=blob_plain%3Bf=ChangeLog%3Bhb=masterhttp://lists.apple.com/archives/security-announce/2011/Mar/msg00006.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/051905.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052401.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.htmlhttp://openwall.com/lists/oss-security/2010/12/03/1http://openwall.com/lists/oss-security/2010/12/03/3http://openwall.com/lists/oss-security/2010/12/03/6http://secunia.com/advisories/42426http://secunia.com/advisories/42523http://secunia.com/advisories/42555http://secunia.com/advisories/42720http://support.apple.com/kb/HT4581http://www.mandriva.com/security/advisories?name=MDVSA-2010:249http://www.securityfocus.com/bid/45152http://www.securitytracker.com/id?1024818http://www.ubuntu.com/usn/USN-1031-1http://www.vupen.com/english/advisories/2010/3135http://www.vupen.com/english/advisories/2010/3137http://www.vupen.com/english/advisories/2010/3185http://xorl.wordpress.com/2010/12/05/cve-2010-4261-clamav-icon_cb-off-by-one/https://bugzilla.redhat.com/show_bug.cgi?id=659861https://wwws.clamav.net/bugzilla/show_bug.cgi?id=2344http://git.clamav.net/gitweb?p=clamav-devel.git%3Ba=blob_plain%3Bf=ChangeLog%3Bhb=masterhttp://lists.apple.com/archives/security-announce/2011/Mar/msg00006.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/051905.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052401.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.htmlhttp://openwall.com/lists/oss-security/2010/12/03/1http://openwall.com/lists/oss-security/2010/12/03/3http://openwall.com/lists/oss-security/2010/12/03/6http://secunia.com/advisories/42426http://secunia.com/advisories/42523http://secunia.com/advisories/42555http://secunia.com/advisories/42720http://support.apple.com/kb/HT4581http://www.mandriva.com/security/advisories?name=MDVSA-2010:249http://www.securityfocus.com/bid/45152http://www.securitytracker.com/id?1024818http://www.ubuntu.com/usn/USN-1031-1http://www.vupen.com/english/advisories/2010/3135http://www.vupen.com/english/advisories/2010/3137http://www.vupen.com/english/advisories/2010/3185http://xorl.wordpress.com/2010/12/05/cve-2010-4261-clamav-icon_cb-off-by-one/https://bugzilla.redhat.com/show_bug.cgi?id=659861https://wwws.clamav.net/bugzilla/show_bug.cgi?id=2344
2010-12-07
Published