← Back

CVE-2021-27506

nvd nist
Published: Mar 19, 2021Modified: Jun 17, 2026

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

The ClamAV Engine (version 0.103.1 and below) component embedded in Storsmshield Network Security (SNS) is subject to DoS in case of parsing of malformed png files. This affect Netasq versions 9.1.0 to 9.1.11 and SNS versions 1.0.0 to 4.2.0. This issue is fixed in SNS 3.7.19, 3.11.7 and 4.2.1.

Affected (3)

Netasq
1 product
Stormshield Network Security
1 product
Clamav
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
From 9.1.0 to 9.1.11
From 1.0 to 4.2.0
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 0.103.1

References (4)

Source: cve@mitre.org
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.