CVE-2019-1789: ClamAV Denial of Service Vulnerability
Published Nov 5, 2019
·Updated
ClamAV versions prior to 0.101.2 are susceptible to a denial of service (DoS) vulnerability. An out-of-bounds heap read condition may occur when scanning PE files. An example is Windows EXE and DLL files that have been packed using Aspack as a result of inadequate bound-checking.
Affected Software
1 affected component
clamav clamav<0.101.2
Event History
Nov 5, 2019
CVE Published
via MITRE·06:25 PM
Data Sourced
via MITRE·06:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2019-1789?
CVE-2019-1789 is a denial of service (DoS) vulnerability in ClamAV versions prior to 0.101.2.
2
How severe is CVE-2019-1789?
CVE-2019-1789 has a severity rating of 7.5, which is considered high.
3
Which software versions are affected by CVE-2019-1789?
ClamAV versions prior to 0.101.2 are affected by CVE-2019-1789.
4
What is the impact of CVE-2019-1789?
The vulnerability can lead to a denial of service (DoS) due to an out-of-bounds heap read condition when scanning certain PE files.
5
How can I mitigate CVE-2019-1789?
To mitigate CVE-2019-1789, update ClamAV to version 0.101.2 or later.