CVE-2021-27506:ClamAV Engine (version 0.103.1 and below) is vulnerable to a Denial of Service (DoS) when parsing malformed PNG files.

splash
Back

Description Preview

The ClamAV Engine component embedded in Stormshield Network Security (SNS) contains a vulnerability that can lead to a Denial of Service condition when parsing malformed PNG files. This vulnerability affects ClamAV versions 0.103.1 and below, impacting Netasq versions 9.1.0 to 9.1.11 and SNS versions 1.0.0 to 4.2.0. Attackers could potentially exploit this vulnerability by submitting specially crafted PNG files to systems running the affected ClamAV versions, causing the service to crash or become unresponsive.

Overview

This vulnerability (CVE-2021-27506) affects the ClamAV antivirus engine when processing PNG files. The issue lies in the PNG file parser, which can be triggered by malformed PNG files, resulting in a Denial of Service condition. When ClamAV scans a maliciously crafted PNG file, the engine may crash or become unresponsive, potentially affecting the availability of security services that rely on ClamAV for malware detection. This vulnerability is particularly concerning for systems that automatically scan user-submitted files, such as email gateways, file upload portals, and network security appliances like Stormshield Network Security.

Remediation

To mitigate this vulnerability, users should update to the following patched versions:

  • For Stormshield Network Security (SNS): Update to version 3.7.19, 3.11.7, or 4.2.1 or later
  • For standalone ClamAV installations: Update to version 0.103.2 or later

If immediate updates are not possible, consider implementing the following temporary measures:

  1. Limit PNG file uploads or scanning where possible
  2. Implement additional filtering for PNG files before they reach ClamAV scanning
  3. Monitor system resources and implement automatic service restarts if ClamAV crashes
  4. Consider deploying additional security layers that don't rely solely on ClamAV

References

  1. Stormshield Security Advisory: https://advisories.stormshield.eu/2021-003/
  2. ClamAV Patch Release Announcement: https://blog.clamav.net/2021/02/clamav-01031-patch-release.html
  3. ClamAV Official Documentation: https://docs.clamav.net/
  4. CVE-2021-27506 in the National Vulnerability Database: https://nvd.nist.gov/vuln/detail/CVE-2021-27506

Industry ExposureMost to least
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.

  1. Transportation & Warehousing
    Transportation & Warehousing
  2. Accommodation & Food Services
    Accommodation & Food Services
  3. Administrative, Support, Waste Management & Remediation Services
    Administrative, Support, Waste Management & Remediation Services
  4. Agriculture, Forestry Fishing & Hunting
    Agriculture, Forestry Fishing & Hunting
  5. Arts, Entertainment & Recreation
    Arts, Entertainment & Recreation
  6. Construction
    Construction
  7. Educational Services
    Educational Services
  8. Finance and Insurance
    Finance and Insurance
  9. Health Care & Social Assistance
    Health Care & Social Assistance
  10. Information
    Information
  11. Management of Companies & Enterprises
    Management of Companies & Enterprises
  12. Manufacturing
    Manufacturing
  13. Mining
    Mining
  14. Other Services (except Public Administration)
    Other Services (except Public Administration)
  15. Professional, Scientific, & Technical Services
    Professional, Scientific, & Technical Services
  16. Public Administration
    Public Administration
  17. Real Estate Rental & Leasing
    Real Estate Rental & Leasing
  18. Retail Trade
    Retail Trade
  19. Utilities
    Utilities
  20. Wholesale Trade
    Wholesale Trade

Focus on What Matters

  1. See Everything.
  2. Identify True Risk.
  3. Proactively Mitigate Threats.

Let's talk!

background