ClamAV versions prior to 0.101.2 are susceptible to a denial of service (DoS) vulnerability. An out-of-bounds heap read condition may occur when scanning PE files. An example is Windows EXE and DLL files that have been packed using Aspack as a result of inadequate bound-checking.
{ "vanir_signatures": [ { "id": "CVE-2019-1789-ddd56984", "target": { "file": "libclamav/bytecode_api.h" }, "digest": { "line_hashes": [ "46140468227283298906415223082351219139", "57637809431350785060779079260997518524", "315377670216426981322169424355319031416", "62954451815409499658667418031416508646", "93886038266773758450128167517932370190", "153102776602187404725438308063627314641", "2336673796746868529423457794252560671" ], "threshold": 0.9 }, "signature_version": "v1", "signature_type": "Line", "source": "https://github.com/cisco-talos/clamav/commit/5e0e479ad2276414b624e4494ba27359dac9afcc", "deprecated": false } ] }