CVE-2019-1789
published 2019-11-05CVE-2019-1789: ClamAV versions prior to 0.101.2 are susceptible to a denial of service (DoS) vulnerability. An out-of-bounds heap read condition may occur when scanning PE…
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.49%
71.3th percentile
ClamAV versions prior to 0.101.2 are susceptible to a denial of service (DoS) vulnerability. An out-of-bounds heap read condition may occur when scanning PE files. An example is Windows EXE and DLL files that have been packed using Aspack as a result of inadequate bound-checking.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | clamav | >= unspecified < 0.100.3 | 0.100.3 |
| clamav | clamav | < 0.101.2 | 0.101.2 |
| clamav | clamav | >= 0 < 0.101.2+dfsg-1 | 0.101.2+dfsg-1 |
| clamav | clamav | >= 0 < 0.101.2+dfsg-1 | 0.101.2+dfsg-1 |
| clamav | clamav | >= 0 < 0.101.2+dfsg-1 | 0.101.2+dfsg-1 |
| clamav | clamav | >= 0 < 0.101.2+dfsg-1 | 0.101.2+dfsg-1 |
| clamav | clamav | >= 0 < 0.100.3+dfsg-0ubuntu0.14.04.1 | 0.100.3+dfsg-0ubuntu0.14.04.1 |
| clamav | clamav | >= 0 < 0.100.3+dfsg-0ubuntu0.16.04.1 | 0.100.3+dfsg-0ubuntu0.16.04.1 |
| clamav | clamav | >= 0 < 0.100.3+dfsg-0ubuntu0.18.04.1 | 0.100.3+dfsg-0ubuntu0.18.04.1 |
| debian | clamav | < clamav 0.101.2+dfsg-1 (bookworm) | clamav 0.101.2+dfsg-1 (bookworm) |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ccg9-2v2c-6xww: ClamAV versions prior to 0
ghsa_unreviewed·2022-05-24
CVE-2019-1789 [MEDIUM] GHSA-ccg9-2v2c-6xww: ClamAV versions prior to 0
ClamAV versions prior to 0.101.2 are susceptible to a denial of service (DoS) vulnerability. An out-of-bounds heap read condition may occur when scanning PE files. An example is Windows EXE and DLL files that have been packed using Aspack as a result of inadequate bound-checking.
OSV
CVE-2019-1789: ClamAV versions prior to 0
osv·2019-11-05·CVSS 7.5
CVE-2019-1789 [HIGH] CVE-2019-1789: ClamAV versions prior to 0
ClamAV versions prior to 0.101.2 are susceptible to a denial of service (DoS) vulnerability. An out-of-bounds heap read condition may occur when scanning PE files. An example is Windows EXE and DLL files that have been packed using Aspack as a result of inadequate bound-checking.
OSV
clamav vulnerabilities
osv·2019-04-08·CVSS 5.5
CVE-2019-1787 [MEDIUM] clamav vulnerabilities
clamav vulnerabilities
It was discovered that ClamAV incorrectly handled scanning certain PDF
documents. A remote attacker could possibly use this issue to cause ClamAV
to crash, resulting in a denial of service. (CVE-2019-1787)
It was discovered that ClamAV incorrectly handled scanning certain OLE2
files. A remote attacker could use this issue to cause ClamAV to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2019-1788)
It was discovered that ClamAV incorrectly handled scanning certain PE
files. A remote attacker could possibly use this issue to cause ClamAV to
crash, resulting in a denial of service. (CVE-2019-1789)
Ubuntu
ClamAV vulnerabilities
vendor_ubuntu·2019-04-08·CVSS 5.5
CVE-2019-1787 [MEDIUM] ClamAV vulnerabilities
Title: ClamAV vulnerabilities
Summary: Several security issues were fixed in ClamAV.
It was discovered that ClamAV incorrectly handled scanning certain PDF
documents. A remote attacker could possibly use this issue to cause ClamAV
to crash, resulting in a denial of service. (CVE-2019-1787)
It was discovered that ClamAV incorrectly handled scanning certain OLE2
files. A remote attacker could use this issue to cause ClamAV to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2019-1788)
It was discovered that ClamAV incorrectly handled scanning certain PE
files. A remote attacker could possibly use this issue to cause ClamAV to
crash, resulting in a denial of service. (CVE-2019-1789)
Instructions: This update uses a new upstream release, which includes add
Ubuntu
ClamAV vulnerabilities
vendor_ubuntu·2019-04-08·CVSS 5.5
CVE-2019-1787 [MEDIUM] ClamAV vulnerabilities
Title: ClamAV vulnerabilities
Summary: Several security issues were fixed in ClamAV.
USN-3940-1 fixed several vulnerabilities in ClamAV. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that ClamAV incorrectly handled scanning certain PDF
documents. A remote attacker could possibly use this issue to cause ClamAV
to crash, resulting in a denial of service. (CVE-2019-1787)
It was discovered that ClamAV incorrectly handled scanning certain OLE2
files. A remote attacker could use this issue to cause ClamAV to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2019-1788)
It was discovered that ClamAV incorrectly handled scanning certain PE
files. A remote attacker could possibly use this issue t
Debian
CVE-2019-1789: clamav - ClamAV versions prior to 0.101.2 are susceptible to a denial of service (DoS) vu...
vendor_debian·2019·CVSS 7.5
CVE-2019-1789 [HIGH] CVE-2019-1789: clamav - ClamAV versions prior to 0.101.2 are susceptible to a denial of service (DoS) vu...
ClamAV versions prior to 0.101.2 are susceptible to a denial of service (DoS) vulnerability. An out-of-bounds heap read condition may occur when scanning PE files. An example is Windows EXE and DLL files that have been packed using Aspack as a result of inadequate bound-checking.
Scope: local
bookworm: resolved (fixed in 0.101.2+dfsg-1)
bullseye: resolved (fixed in 0.101.2+dfsg-1)
forky: resolved (fixed in 0.101.2+dfsg-1)
sid: resolved (fixed in 0.101.2+dfsg-1)
trixie: resolved (fixed in 0.101.2+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-10171 389-ds-base: Insufficient fix for CVE-2018-14648 denial of service in RHEL-7.5
bugzilla·2019-06-19·CVSS 7.5
CVE-2019-10171 [HIGH] CVE-2019-10171 389-ds-base: Insufficient fix for CVE-2018-14648 denial of service in RHEL-7.5
CVE-2019-10171 389-ds-base: Insufficient fix for CVE-2018-14648 denial of service in RHEL-7.5
I was found that the fix present in RHEL-7.5 RHSA-2018:3507 for flaw CVE-2018-14648 was not sufficient.
Other RHEL versions are not affected.
Discussion:
The CVE was partially fixed, following upstream fix was missing in the original RHEL-7.5 build :
https://pagure.io/389-ds-base/c/722a6f8679
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7.5 Extended Update Support
Via RHSA-2019:1789 https://access.redhat.com/errata/RHSA-2019:1789
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-10171
Bugzilla
CVE-2019-1789 clamav: out-of-bounds heap read when scanning PE files
bugzilla·2019-04-04·CVSS 7.5
CVE-2019-1789 [HIGH] CVE-2019-1789 clamav: out-of-bounds heap read when scanning PE files
CVE-2019-1789 clamav: out-of-bounds heap read when scanning PE files
An out-of-bounds heap read condition may occur when scanning PE files (i.e. Windows EXE and DLL files) that have been packed using Aspack as a result of inadequate bound-checking.
Reference:
https://blog.clamav.net/2019/03/clamav-01012-and-01003-patches-have.html
Discussion:
Created clamav tracking bugs for this issue:
Affects: fedora-all [bug 1696145]
---
Created clamav tracking bugs for this issue:
Affects: epel-all [bug 1696146]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.
Bugzilla
CVE-2019-1785 CVE-2019-1786 CVE-2019-1787 CVE-2019-1788 CVE-2019-1789 CVE-2019-1798 clamav: various flaws [epel-all]
bugzilla·2019-04-04·CVSS 7.8
CVE-2019-1785 [HIGH] CVE-2019-1785 CVE-2019-1786 CVE-2019-1787 CVE-2019-1788 CVE-2019-1789 CVE-2019-1798 clamav: various flaws [epel-all]
CVE-2019-1785 CVE-2019-1786 CVE-2019-1787 CVE-2019-1788 CVE-2019-1789 CVE-2019-1798 clamav: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issu
Bugzilla
CVE-2019-1785 CVE-2019-1786 CVE-2019-1787 CVE-2019-1788 CVE-2019-1789 CVE-2019-1798 clamav: various flaws [fedora-all]
bugzilla·2019-04-04·CVSS 7.8
CVE-2019-1785 [HIGH] CVE-2019-1785 CVE-2019-1786 CVE-2019-1787 CVE-2019-1788 CVE-2019-1789 CVE-2019-1798 clamav: various flaws [fedora-all]
CVE-2019-1785 CVE-2019-1786 CVE-2019-1787 CVE-2019-1788 CVE-2019-1789 CVE-2019-1798 clamav: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
2019-11-05
Published