Vulnerability Name:

CVE-2021-1404 (CCN-199690)

Assigned:2020-11-13
Published:2021-04-07
Updated:2022-08-05
Summary:A vulnerability in the PDF parsing module in Clam AntiVirus (ClamAV) Software versions 0.103.0 and 0.103.1 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper buffer size tracking that may result in a heap buffer over-read. An attacker could exploit this vulnerability by sending a crafted PDF file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to crash, resulting in a denial of service condition.
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-125
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2021-1404

Source: CCN
Type: ClamAV Blog, Wednesday, April 7, 2021
ClamAV 0.103.2 security patch release

Source: CISCO
Type: Release Notes, Vendor Advisory
https://blog.clamav.net/2021/04/clamav-01032-security-patch-release.html

Source: XF
Type: UNKNOWN
clamav-cve20211404-dos(199690)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:clamav:clamav:0.103.0:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.103.1:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:clamav:clamav:0.103.0:*:*:*:*:*:*:*
  • OR cpe:/a:clamav:clamav:0.103.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:7463
    P
    clamav-0.103.8-150000.3.44.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:3383
    P
    tftp-5.2-11.6.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:2889
    P
    clamav-0.103.5-3.35.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94519
    P
    clamav-0.103.5-3.35.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94495
    P
    arm-trusted-firmware-2.6-150400.4.7 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:27
    P
    clamav-0.103.2-3.26.1 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:956
    P
    Security update for expat (Important)
    2022-03-04
    oval:org.opensuse.security:def:112078
    P
    clamav-0.103.3-1.4 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:99439
    P
    (Important)
    2021-12-06
    oval:org.opensuse.security:def:105621
    P
    clamav-0.103.3-1.4 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:101208
    P
    libnetpbm-devel-10.80.1-3.11.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62045
    P
    clamav-0.103.2-3.26.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100803
    P
    clamav-0.103.2-3.26.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:71786
    P
    clamav-0.103.2-3.26.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:99638
    P
    (Important)
    2021-06-01
    oval:org.opensuse.security:def:99943
    P
    (Important)
    2021-05-19
    oval:org.opensuse.security:def:111323
    P
    Security update for clamav (Important)
    2021-04-15
    oval:org.opensuse.security:def:70200
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:31151
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:59715
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:99045
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:40062
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:55885
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:86534
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:96849
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:73594
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:82554
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:8934
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:92290
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:125517
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:33634
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:69446
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:29347
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:57893
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:89112
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:107874
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:51537
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:84583
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:10060
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:93040
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:70380
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:31606
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:99240
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:41231
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:56005
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:87361
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:43195
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:83269
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:9306
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:92489
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:126688
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:33892
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:69630
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:30062
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:58720
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:89370
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:38103
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:51872
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:85615
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:10240
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:93193
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:8561
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:91900
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:32070
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:23549
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:56974
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:88101
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:44492
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:83389
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:9490
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:92688
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:127085
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:69829
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:30182
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:59457
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:98850
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:38765
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:55170
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:86070
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:8739
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:92095
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:117389
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:32897
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:64472
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:23884
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:57429
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:88413
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:45661
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:84126
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:9689
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:92887
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:60228
    P
    Security update for clamav (Important)
    2021-04-13
    oval:org.opensuse.security:def:34405
    P
    Security update for clamav (Important)
    2021-04-13
    BACK
    clamav clamav 0.103.0
    clamav clamav 0.103.1
    clamav clamav 0.103.0
    clamav clamav 0.103.1