Input validation error in ClamAV - CVE-2019-15961

 

Input validation error in ClamAV - CVE-2019-15961

Published: December 12, 2019


Vulnerability identifier: #VU23559
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-15961
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input passed via email messages due to overly long parsing of MIME messages. A remote attacker can send a specially crafted email message and perform a denial of service attack.


Affected software

ClamAV
Gentoo Linux
Amazon Linux AMI
Fedora
Opensuse
openEuler
clamav (Ubuntu package)
clamav (Alpine package)
clamav
clamav-help
clamav-update
clamav-milter
clamav-debuginfo
clamd
clamav-devel
clamav-debugsource
clamav-filesystem
clamav-data
RSA Authentication Manager

How to mitigate CVE-2019-15961

Install updates from vendor's website.

ClamAV - addressed in versions 0.101.5, 0.102.1
clamav (Ubuntu package) - addressed in versions 0.102.1+dfsg-0ubuntu0.16.04.2, 0.102.1+dfsg-0ubuntu0.18.04.2, 0.102.1+dfsg-0ubuntu0.19.04.2, 0.102.1+dfsg-0ubuntu0.19.10.2
clamav (Alpine package) - update to 0.101.5-r0
clamav - update to 0.101.4-9
clamav-help - update to 0.101.4-9
clamav-update - update to 0.101.4-9
clamav-milter - update to 0.101.4-9
clamav-debuginfo - update to 0.101.4-9
clamd - update to 0.101.4-9
clamav-devel - update to 0.101.4-9
clamav-debugsource - update to 0.101.4-9
clamav-filesystem - update to 0.101.4-9
clamav-data - update to 0.101.4-9
clamav - addressed in versions 0.101.5-1.el7, 0.101.5-1.el8, 0.101.5-1.fc29, 0.101.5-1.fc30, 0.101.5-1.fc31
RSA Authentication Manager - addressed in versions 8.4 Patch 10, 8.5 Patch 3

External References

Related Security Bulletins