
Cloud Vulnerability DB
A community-led vulnerabilities database
The ClamAV Engine (version 0.103.1 and below) component embedded in Stormshield Network Security (SNS) contains a vulnerability that can lead to a Denial of Service (DoS) condition when parsing malformed PNG files. This vulnerability affects Netasq versions 9.1.0 to 9.1.11 and SNS versions 1.0.0 to 4.2.0. The issue was discovered on February 3, 2021, and was assigned CVE-2021-27506 (NVD, Stormshield Advisory).
The vulnerability stems from PNG parser logic bugs that caused an excess of parsing errors and a stack exhaustion issue when scanning PNG files. Due to these issues, PNG file type detection was initially disabled via signature database update for ClamAV version 0.103.0 as a mitigation measure. The vulnerability has been assigned a CVSS v3.1 Base Score of 5.5 (Medium) with the vector string CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H (NVD, ClamAV Blog).
When exploited, this vulnerability can cause the ClamAV service to crash, resulting in a denial of service condition. The impact is limited to availability, with no direct effect on confidentiality or integrity of the system. The vulnerability requires the parsing of malformed PNG files to trigger the DoS condition (Stormshield Advisory).
The vulnerability can be triggered by submitting malformed PNG files for scanning by the ClamAV engine. The attack requires no special privileges but does need user interaction to process the malformed files. The exploit complexity is rated as low, indicating that the vulnerability is relatively straightforward to exploit (NVD).
The vulnerability has been fixed in SNS versions 3.7.19, 3.11.7, and 4.2.1. As a workaround, users can update their ClamAV database to prevent the vulnerability from being triggered, as ClamAV released a signature in their database to prevent this vulnerability. Systems are not vulnerable if ClamAV is not used or if the last update of the ClamAV database is after February 3, 2021 (Stormshield Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."