CVE-2013-2021: Buffer Overflow
Published May 13, 2013
·Updated
pdf.c in ClamAV 0.97.1 through 0.97.7 allows remote attackers to cause a denial of service (out-of-bounds-read) via a crafted length value in an encrypted PDF file.
Affected Software
14 affected components
Canonical Ubuntu Linux=10.04
Canonical Ubuntu Linux=11.10
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=12.10
Canonical Ubuntu Linux=13.04
SUSE Linux Enterprise Server=11.0-sp1
SUSE Linux Enterprise Server=11.0-sp2
clamav clamav=0.97.1
clamav clamav=0.97.2
clamav clamav=0.97.3
clamav clamav=0.97.4
clamav clamav=0.97.5
clamav clamav=0.97.6
clamav clamav=0.97.7
Event History
May 13, 2013
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
Can CVE-2013-2021 be exploited remotely?
Yes, CVE-2013-2021 can be exploited remotely by attackers using a crafted encrypted PDF file.