Executive Summary
A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PESpin files during scanning, which may result in an integer overflow. The vulnerability has a CVSS score of 7.5 and is not currently being actively exploited.
Technical Analysis
The vulnerability is classified as an integer overflow vulnerability in the PESpin file format parser of ClamAV. The attack vector is through the submission of a crafted file that contains PESpin content to be scanned by ClamAV on an affected device. The root cause is improper boundary checks for content in PESpin files during scanning.
How It Gets Exploited
An unauthenticated, remote attacker could exploit this vulnerability by submitting a crafted file that contains PESpin content to be scanned by ClamAV on an affected device. The attacker would send the crafted file to the ClamAV scanning process, which would then trigger the integer overflow vulnerability. This would cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Impact Assessment
The following products and versions are affected:
- Cisco Secure Endpoint: 7.0.5, 6.2.19, 7.3.3, 7.2.13, 6.1.5, 6.3.1, 6.2.5, 7.3.5, 6.2.1, 7.2.7, 7.1.1, 6.3.5, 6.2.9, 7.3.1, 6.1.7, 7.2.11, 7.2.3, 7.1.5, 6.3.3, 7.3.9, 6.2.3, 6.1.9, 6.0.9, 7.2.5, 6.0.7, 6.3.7, 1.12.3, 1.8.0, 1.11.1, 1.12.4, 1.10.0, 1.12.0, 1.8.1, 1.10.1, 1.12.1, 1.12.6, 1.14.0, 1.10.2, 1.12.7, 1.12.2, 1.6.0, 1.9.0, 1.11.0, 1.7.0, 1.13.0, 1.8.4, 1.13.1, 1.9.1, 1.12.5, 1.13.2
- Cisco Secure Endpoint: 8.1.7.21512, 8.1.7, 8.1.5, 8.1.3.21242, 8.1.3, 8.1.5.21322, 8.1.7.21417
The vulnerability could allow an attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device.
Recommended Actions
To mitigate this vulnerability, update ClamAV to a version that is not affected by this vulnerability. Specifically, update to a version that includes the fix for this vulnerability.
Sources
- National Vulnerability Database (NVD)