First published: Mon May 13 2013(Updated: )
pdf.c in ClamAV 0.97.1 through 0.97.7 allows remote attackers to cause a denial of service (out-of-bounds-read) via a crafted length value in an encrypted PDF file.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu | =10.04 | |
Ubuntu | =11.10 | |
Ubuntu | =12.04 | |
Ubuntu | =12.10 | |
Ubuntu | =13.04 | |
SUSE Linux Enterprise Server | =11.0-sp1 | |
SUSE Linux Enterprise Server | =11.0-sp2 | |
ClamAV | =0.97.1 | |
ClamAV | =0.97.2 | |
ClamAV | =0.97.3 | |
ClamAV | =0.97.4 | |
ClamAV | =0.97.5 | |
ClamAV | =0.97.6 | |
ClamAV | =0.97.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Yes, CVE-2013-2021 can be exploited remotely by attackers using a crafted encrypted PDF file.