SB2020052145 - Out-of-bounds read in clamav (Alpine package)
Published: May 21, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2020-3341)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition within the AES decryption routines when processing PDF files in ClamAV. A remote attacker can create a specially crafted file, pass it to the application, trigger an out-of-bounds read error and crash the service.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=08accee45c774482278c0007d73ec978f6e1e9f9
- https://git.alpinelinux.org/aports/commit/?id=f468b1fb3fb7fe47bc6f66d5096d8dcffe858265
- https://git.alpinelinux.org/aports/commit/?id=c3b1760dc5a495bc548332cf430b22a5bca68e87
- https://git.alpinelinux.org/aports/commit/?id=8e39ea63fd40571929d4d61e03a300bb9339d870