CVE-2013-2021
published 2013-05-13CVE-2013-2021: pdf.c in ClamAV 0.97.1 through 0.97.7 allows remote attackers to cause a denial of service (out-of-bounds-read) via a crafted length value in an encrypted PDF…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
3.50%
87.9th percentile
pdf.c in ClamAV 0.97.1 through 0.97.7 allows remote attackers to cause a denial of service (out-of-bounds-read) via a crafted length value in an encrypted PDF file.
Affected
52 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | >= 0 < 0.97.8+dfsg-1 | 0.97.8+dfsg-1 |
| clamav | clamav | >= 0 < 0.97.8+dfsg-1 | 0.97.8+dfsg-1 |
| clamav | clamav | >= 0 < 0.97.8+dfsg-1 | 0.97.8+dfsg-1 |
| clamav | clamav | >= 0 < 0.97.8+dfsg-1 | 0.97.8+dfsg-1 |
| debian | clamav | < clamav 0.97.8+dfsg-1 (bookworm) | clamav 0.97.8+dfsg-1 (bookworm) |
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
| msrc | microsoft_excel_2010_service_pack_2 | — | — |
| msrc | microsoft_excel_2013_rt_service_pack_1 | — | — |
| msrc | microsoft_excel_2013_service_pack_1 | — | — |
| msrc | microsoft_excel_2016 | — | — |
| msrc | microsoft_exchange_server_2010_service_pack_3 | — | — |
| msrc | microsoft_exchange_server_2013_cumulative_update_21 | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_msrc9.1CRITICAL
vendor_oracle7.6HIGH
vendor_ubuntu5.0MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Exchange Server Remote Code Execution Vulnerability
vendor_msrc·2021-03-09·CVSS 9.1
CVE-2021-26855 [CRITICAL] Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
FAQ: Is this vulnerability being used in an active attack?
Yes. The vulnerability described in this CVE is one of four vulnerabilities that are being exploited in an active attack. The security updates address this attack. More information can be found here: https://msrc-blog.microsoft.com/2021/03/02/multiple-security-updates-released-for-exchange-server.
What is the target for this attack?
The initial attack in this attack chain targets an Exchange On-prem server that is able to receive untrusted connections from an external source. In addition, the Exchange server would need to be running Microsoft Exchange Server 2013, 2016, or 2019.
Where can I get more information about how to protect myself from the vulnerabilities?
Pleas
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: BI Publisher Security — CVE-2021-2013
vendor_oracle·2021-01-15·CVSS 7.6
CVE-2021-2013 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: BI Publisher Security — CVE-2021-2013
Oracle Oracle Fusion Middleware Risk Matrix: BI Publisher Security vulnerability
CVE: CVE-2021-2013
CVSS: 7.6
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Ubuntu
ClamAV vulnerabilities
vendor_ubuntu·2013-05-03·CVSS 5.0
CVE-2013-2020 [MEDIUM] ClamAV vulnerabilities
Title: ClamAV vulnerabilities
Summary: ClamAV could be made to crash or run programs if it opened a specially
crafted file.
It was discovered that ClamAV would incorrectly parse a UPX-packed
executable, leading to possible inappropriate heap reads. An attacker
could use this issue to cause ClamAV to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2013-2020)
It was discovered that ClamAV would incorrectly parse a PDF document,
potentially writing beyond the size of a static array. An attacker could
use this issue to cause ClamAV to crash, resulting in a denial of service,
or possibly execute arbitrary code. (CVE-2013-2021)
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need
Debian
CVE-2013-2021: clamav - pdf.c in ClamAV 0.97.1 through 0.97.7 allows remote attackers to cause a denial ...
vendor_debian·2013·CVSS 4.3
CVE-2013-2021 [MEDIUM] CVE-2013-2021: clamav - pdf.c in ClamAV 0.97.1 through 0.97.7 allows remote attackers to cause a denial ...
pdf.c in ClamAV 0.97.1 through 0.97.7 allows remote attackers to cause a denial of service (out-of-bounds-read) via a crafted length value in an encrypted PDF file.
Scope: local
bookworm: resolved (fixed in 0.97.8+dfsg-1)
bullseye: resolved (fixed in 0.97.8+dfsg-1)
forky: resolved (fixed in 0.97.8+dfsg-1)
sid: resolved (fixed in 0.97.8+dfsg-1)
trixie: resolved (fixed in 0.97.8+dfsg-1)
GHSA
GHSA-8rc2-m544-5vqh: pdf
ghsa_unreviewed·2022-05-17
CVE-2013-2021 [MEDIUM] CWE-119 GHSA-8rc2-m544-5vqh: pdf
pdf.c in ClamAV 0.97.1 through 0.97.7 allows remote attackers to cause a denial of service (out-of-bounds-read) via a crafted length value in an encrypted PDF file.
OSV
CVE-2013-2021: pdf
osv·2013-05-13·CVSS 4.3
CVE-2013-2021 [MEDIUM] CVE-2013-2021: pdf
pdf.c in ClamAV 0.97.1 through 0.97.7 allows remote attackers to cause a denial of service (out-of-bounds-read) via a crafted length value in an encrypted PDF file.
No detection rules found.
http://blog.clamav.net/2013/04/clamav-0978-has-been-released.htmlhttp://lists.apple.com/archives/security-announce/2013/Sep/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2013/Sep/msg00004.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-June/109514.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-June/109639.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-June/109652.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-May/105575.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-12/msg00006.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00018.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00020.htmlhttp://secunia.com/advisories/53150http://secunia.com/advisories/53182http://support.apple.com/kb/HT5880http://support.apple.com/kb/HT5892http://www.mandriva.com/security/advisories?name=MDVSA-2013:159http://www.openwall.com/lists/oss-security/2013/04/25/2http://www.openwall.com/lists/oss-security/2013/04/29/20http://www.securityfocus.com/bid/59434http://www.ubuntu.com/usn/USN-1816-1https://bugzilla.clamav.net/show_bug.cgi?id=7053https://github.com/vrtadmin/clamav-devel/commit/24ff855c82d3f5c62bc5788a5776cefbffce2971http://blog.clamav.net/2013/04/clamav-0978-has-been-released.htmlhttp://lists.apple.com/archives/security-announce/2013/Sep/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2013/Sep/msg00004.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-June/109514.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-June/109639.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-June/109652.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-May/105575.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-12/msg00006.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00018.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00020.htmlhttp://secunia.com/advisories/53150http://secunia.com/advisories/53182http://support.apple.com/kb/HT5880http://support.apple.com/kb/HT5892http://www.mandriva.com/security/advisories?name=MDVSA-2013:159http://www.openwall.com/lists/oss-security/2013/04/25/2http://www.openwall.com/lists/oss-security/2013/04/29/20http://www.securityfocus.com/bid/59434http://www.ubuntu.com/usn/USN-1816-1https://bugzilla.clamav.net/show_bug.cgi?id=7053https://github.com/vrtadmin/clamav-devel/commit/24ff855c82d3f5c62bc5788a5776cefbffce2971
2013-05-13
Published