CVE-2010-3434: Buffer Overflow
Buffer overflow in the findstreambounds function in pdf.c in libclamav in ClamAV before 0.96.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document. NOTE: some of these details are obtained from third party information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3434?
CVE-2010-3434 has a medium severity level due to its potential to allow a denial of service and possibly execute arbitrary code.
How do I fix CVE-2010-3434?
To fix CVE-2010-3434, upgrade ClamAV to version 0.96.3 or later.
What type of vulnerability is CVE-2010-3434?
CVE-2010-3434 is a buffer overflow vulnerability found in the find_stream_bounds function in libclamav.
Who is affected by CVE-2010-3434?
CVE-2010-3434 affects all versions of ClamAV prior to 0.96.3, including earlier versions down to 0.01.
What can an attacker do with CVE-2010-3434?
An attacker can use CVE-2010-3434 to crash the ClamAV application or potentially execute arbitrary code by sending a crafted PDF document.