CVE-2019-15961
A vulnerability in the email parsing module Clam AntiVirus (ClamAV) Software versions 0.102.0, 0.101.4 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device.
Does this matter?
Lower severity and a low EPSS score (3.14%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability in the email parsing module Clam AntiVirus (ClamAV) Software versions 0.102.0, 0.101.4 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to inefficient MIME parsing routines that result in extremely long scan times of specially formatted email files. An attacker could exploit this vulnerability by sending a crafted email file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to scan the crafted email file indefinitely, resulting in a denial of service condition.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 3.14% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20, CWE-400
- Affected
- clamav/clamav · cisco/email security appliance firmware · canonical/ubuntu linux · debian/debian linux
- Source
- psirt@cisco.com
References
- https://bugzilla.clamav.net/show_bug.cgi?id=12380Exploit, Issue Tracking, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2020/02/msg00016.htmlMailing List, Third Party Advisory
- https://quickview.cloudapps.cisco.com/quickview/bug/CSCvr56010Third Party Advisory
- https://security.gentoo.org/glsa/202003-46Third Party Advisory
- https://usn.ubuntu.com/4230-2/Third Party Advisory
- https://bugzilla.clamav.net/show_bug.cgi?id=12380Exploit, Issue Tracking, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2020/02/msg00016.htmlMailing List, Third Party Advisory
- https://quickview.cloudapps.cisco.com/quickview/bug/CSCvr56010Third Party Advisory
- https://security.gentoo.org/glsa/202003-46Third Party Advisory
- https://usn.ubuntu.com/4230-2/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.