Resource management error in ClamAV - CVE-2019-12625
Published: October 3, 2019
Vulnerability identifier: #VU21530
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12625
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to incorrect processing of large zip archives. A remote attacker can send an overly large zip file and consume all available system resources.
Affected software
ClamAV
clamav (Alpine package)
clamav
Fedora
RSA Authentication Manager
clamav (Alpine package)
clamav
Fedora
RSA Authentication Manager
How to mitigate CVE-2019-12625
Install updates from vendor's website.
ClamAV - update to 0.101.4
clamav - addressed in versions 0.101.4-1.el7, 0.101.4-1.el8, 0.101.4-1.fc29, 0.101.4-1.fc30
RSA Authentication Manager - update to 8.4 Patch 10
clamav - addressed in versions 0.101.4-1.el7, 0.101.4-1.el8, 0.101.4-1.fc29, 0.101.4-1.fc30
RSA Authentication Manager - update to 8.4 Patch 10