Vulnerabilities > CVE-2007-2029 - Resource Management Errors vulnerability in Clam Anti-Virus Clamav 0.84Rc2
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
File descriptor leak in the PDF handler in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service via a crafted PDF file.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 26 | |
Application | 1 |
Common Weakness Enumeration (CWE)
Nessus
NASL family Mandriva Local Security Checks NASL id MANDRAKE_MDKSA-2007-098.NASL description iDefense discovered a stack-based overflow in ClamAV when processing negative values in .cab files. As well, multiple file descriptor leaks were also reported and fixed in chmunpack.c, pdf.c, and dblock.c. This update provides ClamAV 0.90.2 which corrects these problems and provides new functionality. last seen 2020-06-01 modified 2020-06-02 plugin id 25189 published 2007-05-10 reporter This script is Copyright (C) 2007-2019 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/25189 title Mandrake Linux Security Advisory : clamav (MDKSA-2007:098) NASL family Debian Local Security Checks NASL id DEBIAN_DSA-1281.NASL description Several remote vulnerabilities have been discovered in the Clam anti-virus toolkit. The Common Vulnerabilities and Exposures project identifies the following problems : - CVE-2007-1745 It was discovered that a file descriptor leak in the CHM handler may lead to denial of service. - CVE-2007-1997 It was discovered that a buffer overflow in the CAB handler may lead to the execution of arbitrary code. - CVE-2007-2029 It was discovered that a file descriptor leak in the PDF handler may lead to denial of service. last seen 2020-06-01 modified 2020-06-02 plugin id 25098 published 2007-04-30 reporter This script is Copyright (C) 2007-2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/25098 title Debian DSA-1281-1 : clamav - several vulnerabilities
References
- http://www.debian.org/security/2007/dsa-1281
- http://www.securityfocus.com/bid/23656
- http://secunia.com/advisories/25028
- http://secunia.com/advisories/25189
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:098
- http://osvdb.org/34916
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34083