CVE-2010-4260: Medium severity clamav clamav vulnerability
Multiple unspecified vulnerabilities in pdf.c in libclamav in ClamAV before 0.96.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document, aka (1) "bb #2358" and (2) "bb #2396."
Other sources
Two flaws were reported to have been corrected in ClamAV 0.96.5 [1]:
1) Multiple errors within the processing of PDF files can be exploited to e.g. cause a crash. (CVE-2010-4260)
2) An off-by-one error within the "iconcb()" function can be exploited to cause a memory corruption. (CVE-2010-4261)
Current Fedora version of ClamAV is 0.96.4 and is vulnerable to these issues.
[1] http://secunia.com/advisories/42426/
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4260?
CVE-2010-4260 has been classified as a critical vulnerability due to its potential to cause denial of service or execute arbitrary code.
How do I fix CVE-2010-4260?
To fix CVE-2010-4260, upgrade ClamAV to version 0.96.5 or later.
What type of attacks does CVE-2010-4260 enable?
CVE-2010-4260 enables remote attackers to cause application crashes or possibly execute arbitrary code through crafted PDF documents.
Which versions of ClamAV are affected by CVE-2010-4260?
CVE-2010-4260 affects all ClamAV versions prior to 0.96.5.
Is CVE-2010-4260 a local or remote vulnerability?
CVE-2010-4260 is a remote vulnerability, allowing attacks from outside the affected system.