First published: Fri Mar 19 2021(Updated: )
The ClamAV Engine (version 0.103.1 and below) component embedded in Storsmshield Network Security (SNS) is subject to DoS in case of parsing of malformed png files. This affect Netasq versions 9.1.0 to 9.1.11 and SNS versions 1.0.0 to 4.2.0. This issue is fixed in SNS 3.7.19, 3.11.7 and 4.2.1.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netasq Project Netasq | >=9.1.0<=9.1.11 | |
Stormshield Network Security | >=1.0<=4.2.0 | |
Clamav Clamav | <=0.103.1 | |
Stormshield Stormshield Network Security | >=1.0<=4.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27506 refers to a vulnerability in the ClamAV Engine (version 0.103.1 and below) component embedded in Storsmshield Network Security (SNS) that can be exploited to cause a Denial of Service (DoS) when parsing malformed PNG files.
Netasq versions 9.1.0 to 9.1.11 and SNS versions 1.0.0 to 4.2.0 are affected by CVE-2021-27506.
CVE-2021-27506 can be fixed by upgrading to SNS versions 3.7.19, 3.11.7, or 4.2.1.
CVE-2021-27506 has a severity rating of medium with a CVSS score of 5.5.
More information about CVE-2021-27506 can be found at the following references: [1] [2].