VulnerabilityModified
CVE-2021-27506
The ClamAV Engine (version 0.103.1 and below) component embedded in Storsmshield Network Security (SNS) is subject to DoS in case of parsing of malformed png files.
MEDIUM 5.5EPSS 1.31%
Does this matter?
Lower severity and a low EPSS score (1.31%). Track it; it rarely justifies an emergency change on its own.
Description
The ClamAV Engine (version 0.103.1 and below) component embedded in Storsmshield Network Security (SNS) is subject to DoS in case of parsing of malformed png files. This affect Netasq versions 9.1.0 to 9.1.11 and SNS versions 1.0.0 to 4.2.0. This issue is fixed in SNS 3.7.19, 3.11.7 and 4.2.1.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 1.31% probability · 69th percentile
- CISA KEV
- Not listed
- Affected
- netasq project/netasq · stormshield/stormshield network security · clamav/clamav
- Source
- cve@mitre.org
References
- https://advisories.stormshield.eu/2021-003/Broken Link, Vendor Advisory
- https://blog.clamav.net/2021/02/clamav-01031-patch-release.htmlVendor Advisory
- https://advisories.stormshield.eu/2021-003/Broken Link, Vendor Advisory
- https://blog.clamav.net/2021/02/clamav-01031-patch-release.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.