Input validation error in ClamAV - CVE-2019-15961
Published: December 12, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input passed via email messages due to overly long parsing of MIME messages. A remote attacker can send a specially crafted email message and perform a denial of service attack.
Affected software
Gentoo Linux
Amazon Linux AMI
Fedora
Opensuse
openEuler
clamav (Ubuntu package)
clamav (Alpine package)
clamav
clamav-help
clamav-update
clamav-milter
clamav-debuginfo
clamd
clamav-devel
clamav-debugsource
clamav-filesystem
clamav-data
RSA Authentication Manager
How to mitigate CVE-2019-15961
clamav (Ubuntu package) - addressed in versions 0.102.1+dfsg-0ubuntu0.16.04.2, 0.102.1+dfsg-0ubuntu0.18.04.2, 0.102.1+dfsg-0ubuntu0.19.04.2, 0.102.1+dfsg-0ubuntu0.19.10.2
clamav (Alpine package) - update to 0.101.5-r0
clamav - update to 0.101.4-9
clamav-help - update to 0.101.4-9
clamav-update - update to 0.101.4-9
clamav-milter - update to 0.101.4-9
clamav-debuginfo - update to 0.101.4-9
clamd - update to 0.101.4-9
clamav-devel - update to 0.101.4-9
clamav-debugsource - update to 0.101.4-9
clamav-filesystem - update to 0.101.4-9
clamav-data - update to 0.101.4-9
clamav - addressed in versions 0.101.5-1.el7, 0.101.5-1.el8, 0.101.5-1.fc29, 0.101.5-1.fc30, 0.101.5-1.fc31
RSA Authentication Manager - addressed in versions 8.4 Patch 10, 8.5 Patch 3
External References
Related Security Bulletins
- Denial of service in ClamAV
- OpenSUSE Linux update for clamav
- Ubuntu update for ClamAV
- Amazon Linux AMI update for clamav
- Gentoo update for ClamAV
- Input validation error in clamav (Alpine package)
- openEuler update for clamav
- Fedora EPEL 7 update for clamav
- Fedora EPEL 8 update for clamav
- Fedora 29 update for clamav
- Fedora 30 update for clamav
- Fedora 31 update for clamav
- RSA Authentication Manager update for third-party components
- RSA Authentication Manager update for third-party components