Description
A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device.
This vulnerability is due to improper boundary checks for content in PDF files during scanning, which may result in an out-of-bounds buffer read. An attacker could exploit this vulnerability by submitting a crafted PDF file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 debian 13 | | =1.4.3+dfsg-1 || =1.4.3+dfsg-2 || =1.4.4+dfsg-1 || =1.4.4+dfsg-2 || =1.4.5+dfsg-1 || =1.4.5+dfsg-2 || =1.4.5+dfsg-3 || =1.4.6+dfsg-1 | - |
 debian 12 | | =1.0.1+dfsg-2 || =1.0.2+dfsg-1 || =1.0.2+dfsg-1~deb12u1 || =1.0.3+dfsg-1 || =1.0.3+dfsg-1~deb12u1 || =1.0.3+dfsg-2 || =1.0.4+dfsg-1 || =1.0.5+dfsg-1 || =1.0.5+dfsg-1.1 || =1.0.5+dfsg-1~deb12u1 || =1.0.6+dfsg-1 || =1.0.7+dfsg-1~deb11u1 || =1.0.7+dfsg-1~deb11u2 || =1.0.7+dfsg-1~deb12u1 || =1.0.9+dfsg-1~deb11u1 || =1.0.9+dfsg-1~deb12u1 || =1.2.1+dfsg-1 || =1.2.1+dfsg-2 || =1.2.1+dfsg-3 || =1.3.1+dfsg-1 || =1.3.1+dfsg-2 || =1.3.1+dfsg-3 || =1.3.1+dfsg-4 || =1.3.1+dfsg-5 || =1.4.1+dfsg-1 || =1.4.2+dfsg-1 || =1.4.3+dfsg-1 || =1.4.3+dfsg-1~deb11u1 || =1.4.3+dfsg-1~deb12u1 || =1.4.3+dfsg-1~deb12u2 || =1.4.3+dfsg-2 || =1.4.4+dfsg-1 || =1.4.4+dfsg-2 || =1.4.5+dfsg-1 || =1.4.5+dfsg-2 || =1.4.5+dfsg-3 || =1.4.6+dfsg-1 | - |
 debian 14 | | =1.4.3+dfsg-1 || =1.4.3+dfsg-2 || =1.4.4+dfsg-1 || =1.4.4+dfsg-2 || =1.4.5+dfsg-1 || =1.4.5+dfsg-2 || =1.4.5+dfsg-3 || >=0 <1.4.6+dfsg-1 | 1.4.6+dfsg-1 |