---
title: "CVE-2019-1787\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2019-1787?format=md
keywords: index, follow
---

# CVE-2019-1787

Publication date 3 April 2019

Last updated 25 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**5.5 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2019-1787?format=md#impact-score)

Toggle side navigation

## Description

A vulnerability in the Portable Document Format (PDF) scanning
functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and
prior could allow an unauthenticated, remote attacker to cause a denial of
service (DoS) condition on an affected device. The vulnerability is due to
a lack of proper data handling mechanisms within the device buffer while
indexing remaining file data on an affected device. An attacker could
exploit this vulnerability by sending crafted PDF files to an affected
device. A successful exploit could allow the attacker to cause a heap
buffer out-of-bounds read condition, resulting in a crash that could result
in a denial of service condition on an affected device.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| clamav | 18.10 cosmic | Fixed 0.100.3+dfsg-0ubuntu0.18.10.1 |
| 18.04 LTS bionic | Fixed 0.100.3+dfsg-0ubuntu0.18.04.1 |
| 16.04 LTS xenial | Fixed 0.100.3+dfsg-0ubuntu0.16.04.1 |
| 14.04 LTS trusty | Fixed 0.100.3+dfsg-0ubuntu0.14.04.1 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

5.5 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | Required |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | None |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 5.5 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1787)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-1787)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2019-1787)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2019-1787)

### Related Ubuntu Security Notices (USN)

+ [USN-3940-1](https://usn.ubuntu.com/USN-3940-1)
+ ClamAV vulnerabilities
+ 8 April 2019

+ [USN-3940-2](https://usn.ubuntu.com/USN-3940-2)
+ ClamAV vulnerabilities
+ 8 April 2019

### Other references

* <https://blog.clamav.net/2019/03/clamav-01012-and-01003-patches-have.html>
* <https://www.cve.org/CVERecord?id=CVE-2019-1787>
