CVE Vulnerabilities

CVE-2021-27506

Published: Mar 19, 2021 | Modified: Aug 20, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

The ClamAV Engine (version 0.103.1 and below) component embedded in Storsmshield Network Security (SNS) is subject to DoS in case of parsing of malformed png files. This affect Netasq versions 9.1.0 to 9.1.11 and SNS versions 1.0.0 to 4.2.0. This issue is fixed in SNS 3.7.19, 3.11.7 and 4.2.1.

Affected Software

Name Vendor Start Version End Version
Netasq Netasq_project 9.1.0 (including) 9.1.11 (including)
Stormshield_network_security Stormshield 1.0 (including) 4.2.0 (including)

References