MEDIUM 5.5 Microsoft
CVE-2021-27506
The ClamAV Engine (version 0.103.1 and below) component embedded in Storsmshield Network Security (SNS) is subject to DoS in case of parsing of malformed png files. This affect Netasq versions 9.1.0 to 9.1.11 and SNS versions 1.0.0 to 4.2.0. This issue is fixed in SNS 3.7.19 3.11.7 and 4.2.1.
Microsoft Security Update 2021-Mar: The ClamAV Engine (version 0.103.1 and below) component embedded in Storsmshield Network Security (SNS) is subject to DoS in case of parsing of malformed png files. This affect Netasq versions 9.1.0 to 9.1.11 and SNS versions 1.0.0 to 4.2.0. This issue is fixed in SNS 3.7.19 3.11.7 and 4.2.1.
Affected Products
- clamav-0.103.2-1.cm1.x86_64.rpm on CBL Mariner 1.0 x64
- clamav-debuginfo-0.103.2-1.cm1.x86_64.rpm on CBL Mariner 1.0 x64
- clamav-0.103.2-1.cm1.aarch64.rpm on CBL Mariner 1.0 ARM
- clamav-debuginfo-0.103.2-1.cm1.aarch64.rpm on CBL Mariner 1.0 ARM
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-27506
- https://nvd.nist.gov/vuln/detail/CVE-2021-27506
This medium severity vulnerability with a CVSS score of 5.5 was published on 2021-03-09 via Microsoft. Affected: clamav-0.103.2-1.cm1.x86_64.rpm on CBL Mariner 1.0 x64, clamav-debuginfo-0.103.2-1.cm1.x86_64.rpm on CBL Mariner 1.0 x64, clamav-0.103.2-1.cm1.aarch64.rpm on CBL Mariner 1.0 ARM and 1 more.
vulnfeed aggregates 11644 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.