CVE-2010-3434

critical
Published 2010-09-30 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
9.3

Description

Buffer overflow in the find_stream_bounds function in pdf.c in libclamav in ClamAV before 0.96.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document. NOTE: some of these details are obtained from third party information.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

OS impact

debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 0.96.3+dfsg-1
sid Fixed 0.96.3+dfsg-1
forky Fixed 0.96.3+dfsg-1
bullseye Fixed 0.96.3+dfsg-1
bookworm Fixed 0.96.3+dfsg-1

Application impact

VendorProductVersionsFixed
clamavclamav{"endIncluding":"0.96.2"}
clamavclamav0.01
clamavclamav0.02
clamavclamav0.3
clamavclamav0.03
clamavclamav0.05
clamavclamav0.9
clamavclamav0.10
clamavclamav0.12
clamavclamav0.13
clamavclamav0.14
clamavclamav0.15
clamavclamav0.20
clamavclamav0.21
clamavclamav0.22
clamavclamav0.23
clamavclamav0.24
clamavclamav0.51
clamavclamav0.52
clamavclamav0.53
clamavclamav0.54
clamavclamav0.60
clamavclamav0.60p
clamavclamav0.65
clamavclamav0.66
clamavclamav0.67
clamavclamav0.67-1
clamavclamav0.68
clamavclamav0.68.1
clamavclamav0.70
clamavclamav0.71
clamavclamav0.72
clamavclamav0.73
clamavclamav0.74
clamavclamav0.75
clamavclamav0.75.1
clamavclamav0.80
clamavclamav0.81
clamavclamav0.82
clamavclamav0.83
clamavclamav0.84
clamavclamav0.85
clamavclamav0.85.1
clamavclamav0.86
clamavclamav0.86.1
clamavclamav0.86.2
clamavclamav0.87
clamavclamav0.87.1
clamavclamav0.88
clamavclamav0.88.1
clamavclamav0.88.2
clamavclamav0.88.3
clamavclamav0.88.4
clamavclamav0.88.5
clamavclamav0.88.6
clamavclamav0.88.7
clamavclamav0.90
clamavclamav0.90.1
clamavclamav0.90.2
clamavclamav0.90.3
clamavclamav0.90.3_p0
clamavclamav0.90.3_p1
clamavclamav0.91
clamavclamav0.91.1
clamavclamav0.91.2
clamavclamav0.91.2_p0
clamavclamav0.92
clamavclamav0.92.1
clamavclamav0.92_p0
clamavclamav0.93
clamavclamav0.93.1
clamavclamav0.93.2
clamavclamav0.93.3
clamavclamav0.94
clamavclamav0.94.1
clamavclamav0.94.2
clamavclamav0.95
clamavclamav0.95.1
clamavclamav0.95.2
clamavclamav0.95.3
clamavclamav0.96
clamavclamav0.96.1

References

CWEs

CWE-119

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.