Vulnerabilities > CVE-2007-2029 - Resource Management Errors vulnerability in Clam Anti-Virus Clamav 0.84Rc2

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
COMPLETE
network
low complexity
debian
clam-anti-virus
CWE-399
nessus

Summary

File descriptor leak in the PDF handler in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service via a crafted PDF file.

Vulnerable Configurations

Part Description Count
OS
Debian
26
Application
Clam_Anti-Virus
1

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyMandriva Local Security Checks
    NASL idMANDRAKE_MDKSA-2007-098.NASL
    descriptioniDefense discovered a stack-based overflow in ClamAV when processing negative values in .cab files. As well, multiple file descriptor leaks were also reported and fixed in chmunpack.c, pdf.c, and dblock.c. This update provides ClamAV 0.90.2 which corrects these problems and provides new functionality.
    last seen2020-06-01
    modified2020-06-02
    plugin id25189
    published2007-05-10
    reporterThis script is Copyright (C) 2007-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/25189
    titleMandrake Linux Security Advisory : clamav (MDKSA-2007:098)
  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-1281.NASL
    descriptionSeveral remote vulnerabilities have been discovered in the Clam anti-virus toolkit. The Common Vulnerabilities and Exposures project identifies the following problems : - CVE-2007-1745 It was discovered that a file descriptor leak in the CHM handler may lead to denial of service. - CVE-2007-1997 It was discovered that a buffer overflow in the CAB handler may lead to the execution of arbitrary code. - CVE-2007-2029 It was discovered that a file descriptor leak in the PDF handler may lead to denial of service.
    last seen2020-06-01
    modified2020-06-02
    plugin id25098
    published2007-04-30
    reporterThis script is Copyright (C) 2007-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/25098
    titleDebian DSA-1281-1 : clamav - several vulnerabilities