Vulnerability Name:

CVE-2010-3434 (CCN-62127)

Assigned:2010-09-28
Published:2010-09-28
Updated:2011-03-24
Summary:Buffer overflow in the find_stream_bounds function in pdf.c in libclamav in ClamAV before 0.96.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document.
Note: some of these details are obtained from third party information.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
7.1 High (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:TF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
3.3 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:TF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-119
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2010-3434

Source: CONFIRM
Type: UNKNOWN
http://git.clamav.net/gitweb?p=clamav-devel.git;a=blob_plain;f=ChangeLog;hb=clamav-0.96.3

Source: CONFIRM
Type: UNKNOWN
http://git.clamav.net/gitweb?p=clamav-devel.git;a=commit;h=dc5143b4669ae39c79c9af50d569c28c798f33da

Source: CCN
Type: ClamAV GIT Repository
git.clamav.net Git

Source: APPLE
Type: UNKNOWN
APPLE-SA-2011-03-21-1

Source: SUSE
Type: UNKNOWN
SUSE-SR:2010:020

Source: CONFIRM
Type: UNKNOWN
http://security-tracker.debian.org/tracker/CVE-2010-3434

Source: CCN
Type: Apple Web site
About the security content of Mac OS X v10.6.7 and Security Update 2011-001

Source: CONFIRM
Type: UNKNOWN
http://support.apple.com/kb/HT4581

Source: CCN
Type: Clam AntiVirus Web site
Clam AntiVirus

Source: MLIST
Type: UNKNOWN
[oss-security] 20100922 CVE request: clamav < 0.96.3 pdf bounds checking

Source: MLIST
Type: UNKNOWN
[oss-security] 20100927 Re: CVE request: clamav < 0.96.3 pdf bounds checking

Source: MLIST
Type: UNKNOWN
[oss-security] 20100928 Re: CVE request: clamav < 0.96.3 pdf bounds checking

Source: MLIST
Type: UNKNOWN
[oss-security] 20100928 Re: CVE request: clamav < 0.96.3 pdf bounds checking

Source: CCN
Type: OSVDB ID: 68302
ClamAV pdf.c find_stream_bounds Function Crafted PDF File Handling Overflow

Source: CCN
Type: BID-43555
ClamAV 'find_stream_bounds()' PDF File Processing Denial Of Service Vulnerability

Source: VUPEN
Type: Patch, Vendor Advisory
ADV-2010-2455

Source: XF
Type: UNKNOWN
clamav-findstreambounds-dos(62127)

Source: SUSE
Type: SUSE-SR:2010:020
SUSE Security Summary Report

Source: CCN
Type: ClamAV Bugzilla Bug 2226
segmentation fault on an invalid pdf document Summary: segmentation fault on an invalid pdf document

Source: CONFIRM
Type: UNKNOWN
https://wwws.clamav.net/bugzilla/show_bug.cgi?id=2226

Vulnerable Configuration:Configuration 1:
  • cpe:/a:clamav:clamav:0.01:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.02:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.03:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.3:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.05:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.9:rc1:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.10:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.12:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.13:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.14:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.15:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.20:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.21:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.22:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.23:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.24:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.51:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.52:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.53:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.54:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.60:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.60p:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.65:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.66:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.67:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.67-1:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.68:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.68.1:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.70:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.71:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.72:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.73:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.74:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.75:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.75.1:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.80:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.80:rc2:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.80:rc3:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.80:rc4:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.81:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.82:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.83:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.84:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.84:rc1:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.84:rc2:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.85:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.85.1:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.86:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.86:rc1:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.86.1:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.86.2:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.87:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.87.1:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.88:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.88.1:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.88.2:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.88.3:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.88.4:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.88.5:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.88.6:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.88.7:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.90:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.90:rc1:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.90:rc1.1:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.90:rc2:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.90:rc3:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.90.1:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.90.2:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.90.3:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.90.3_p0:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.90.3_p1:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.91:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.91:rc1:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.91:rc2:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.91.1:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.91.2:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.91.2_p0:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.92:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.92.1:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.92_p0:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.93:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.93.1:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.93.2:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.93.3:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.94:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.94.1:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.94.2:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.95:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.95:rc1:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.95:rc2:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.95:src1:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.95:src2:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.95.1:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.95.2:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.95.3:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.96:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.96:rc1:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.96:rc2:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.96.1:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:*:*:*:*:*:*:*:* (Version <= 0.96.2)

  • Configuration CCN 1:
  • cpe:/o:apple:mac_os_x_server:10.6:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.6:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x_server:10.6.1:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.6.1:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x_server:10.6.2:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.6.2:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.6.3:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x_server:10.6.3:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x_server:10.6.4:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.6.4:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.96.2:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x_server:10.6.5:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.6.5:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x_server:10.6.6:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.6.6:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20103434
    V
    CVE-2010-3434
    2022-05-20
    BACK
    clamav clamav 0.01
    clamav clamav 0.02
    clamav clamav 0.03
    clamav clamav 0.3
    clamav clamav 0.05
    clamav clamav 0.9 rc1
    clamav clamav 0.10
    clamav clamav 0.12
    clamav clamav 0.13
    clamav clamav 0.14
    clamav clamav 0.15
    clamav clamav 0.20
    clamav clamav 0.21
    clamav clamav 0.22
    clamav clamav 0.23
    clamav clamav 0.24
    clamav clamav 0.51
    clamav clamav 0.52
    clamav clamav 0.53
    clamav clamav 0.54
    clamav clamav 0.60
    clamav clamav 0.60p
    clamav clamav 0.65
    clamav clamav 0.66
    clamav clamav 0.67
    clamav clamav 0.67-1
    clamav clamav 0.68
    clamav clamav 0.68.1
    clamav clamav 0.70
    clamav clamav 0.71
    clamav clamav 0.72
    clamav clamav 0.73
    clamav clamav 0.74
    clamav clamav 0.75
    clamav clamav 0.75.1
    clamav clamav 0.80
    clamav clamav 0.80 rc2
    clamav clamav 0.80 rc3
    clamav clamav 0.80 rc4
    clamav clamav 0.81
    clamav clamav 0.82
    clamav clamav 0.83
    clamav clamav 0.84
    clamav clamav 0.84 rc1
    clamav clamav 0.84 rc2
    clamav clamav 0.85
    clamav clamav 0.85.1
    clamav clamav 0.86
    clamav clamav 0.86 rc1
    clamav clamav 0.86.1
    clamav clamav 0.86.2
    clamav clamav 0.87
    clamav clamav 0.87.1
    clamav clamav 0.88
    clamav clamav 0.88.1
    clamav clamav 0.88.2
    clamav clamav 0.88.3
    clamav clamav 0.88.4
    clamav clamav 0.88.5
    clamav clamav 0.88.6
    clamav clamav 0.88.7
    clamav clamav 0.90
    clamav clamav 0.90 rc1
    clamav clamav 0.90 rc1.1
    clamav clamav 0.90 rc2
    clamav clamav 0.90 rc3
    clamav clamav 0.90.1
    clamav clamav 0.90.2
    clamav clamav 0.90.3
    clamav clamav 0.90.3_p0
    clamav clamav 0.90.3_p1
    clamav clamav 0.91
    clamav clamav 0.91 rc1
    clamav clamav 0.91 rc2
    clamav clamav 0.91.1
    clamav clamav 0.91.2
    clamav clamav 0.91.2_p0
    clamav clamav 0.92
    clamav clamav 0.92.1
    clamav clamav 0.92_p0
    clamav clamav 0.93
    clamav clamav 0.93.1
    clamav clamav 0.93.2
    clamav clamav 0.93.3
    clamav clamav 0.94
    clamav clamav 0.94.1
    clamav clamav 0.94.2
    clamav clamav 0.95
    clamav clamav 0.95 rc1
    clamav clamav 0.95 rc2
    clamav clamav 0.95 src1
    clamav clamav 0.95 src2
    clamav clamav 0.95.1
    clamav clamav 0.95.2
    clamav clamav 0.95.3
    clamav clamav 0.96
    clamav clamav 0.96 rc1
    clamav clamav 0.96 rc2
    clamav clamav 0.96.1
    clamav clamav *
    apple mac os x server 10.6
    apple mac os x 10.6
    apple mac os x server 10.6.1
    apple mac os x 10.6.1
    apple mac os x server 10.6.2
    apple mac os x 10.6.2
    apple mac os x 10.6.3
    apple mac os x server 10.6.3
    apple mac os x server 10.6.4
    apple mac os x 10.6.4
    clamav clamav 0.96.2
    apple mac os x server 10.6.5
    apple mac os x 10.6.5
    apple mac os x server 10.6.6
    apple mac os x 10.6.6