First published: Tue Nov 05 2019(Updated: )
ClamAV versions prior to 0.101.2 are susceptible to a denial of service (DoS) vulnerability. An out-of-bounds heap read condition may occur when scanning PE files. An example is Windows EXE and DLL files that have been packed using Aspack as a result of inadequate bound-checking.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
ClamAV | <0.101.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-1789 is a denial of service (DoS) vulnerability in ClamAV versions prior to 0.101.2.
CVE-2019-1789 has a severity rating of 7.5, which is considered high.
ClamAV versions prior to 0.101.2 are affected by CVE-2019-1789.
The vulnerability can lead to a denial of service (DoS) due to an out-of-bounds heap read condition when scanning certain PE files.
To mitigate CVE-2019-1789, update ClamAV to version 0.101.2 or later.