CVE-2010-1639: Medium severity clamav clamav vulnerability
The clipdf function in libclamav/pdf.c in ClamAV before 0.96.1 allows remote attackers to cause a denial of service (crash) via a malformed PDF file, related to an inconsistency in the calculated stream length and the real stream length.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1639?
CVE-2010-1639 has a severity rating that indicates it can lead to denial of service attacks through malformed PDF files.
How do I fix CVE-2010-1639?
To fix CVE-2010-1639, upgrade to ClamAV version 0.96.1 or later.
What systems are affected by CVE-2010-1639?
CVE-2010-1639 affects multiple versions of ClamAV including 0.02, 0.15, 0.86.2, and other versions up to 0.96.
How can CVE-2010-1639 be exploited?
CVE-2010-1639 can be exploited by sending a specially crafted PDF file to a vulnerable ClamAV installation, causing a crash.
Is it safe to use older versions of ClamAV with CVE-2010-1639?
Using older versions of ClamAV that are vulnerable to CVE-2010-1639 is not safe as they can be easily targeted for denial of service.