NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
MarkPearce
Aug 14, 2018Aspirant
PDF Exploit
Hi,
I have started to get the follosing error when access some PDF files that have been created by us:
Aug 14 10:53:13 AI-NAS clamd[6579]: ScanOnAccess: /************.pdf: Pdf.Exploit.CVE...
- Aug 14, 2018
MarkPearce wrote:
Aug 14 10:53:13 AI-NAS clamd[6579]: ScanOnAccess: /************.pdf: Pdf.Exploit.CVE_2018_12798-6633682-0(00b60906f9c35e6bb064020fab67804d:1329806) FOUND
Aug 14 10:53:13 AI-NAS clamd[6579]: ERROR: VirusEvent: fork failed.... How do I find out what this exploit is...
Google the CVE (in this case 2018_12798). Nist.gov will give more information ( https://nvd.nist.gov/vuln/detail/CVE-2018-12798 ), and in this case there is also an Adobe security bulletin ( https://helpx.adobe.com/security/products/acrobat/apsb18-21.html )
The threat is that "Successful exploitation could lead to arbitrary code execution in the context of the current user." ClamAV is finding the vulnerability, it isn't saying it was successfully exploited.
Marc_V
Aug 15, 2018NETGEAR Employee Retired
Hi!
You may want to visit https://www.netgear.com/about/security/default.aspx and report vulnerabilities
Thanks for correcting me StephenB. In this case solution should be provided by the party involved. The link I presented is for any NETGEAR involved vulnerability.
the vulnerability is still undergoing analysis though, Im sure there will be a resolution for this once done.
Regards
StephenB
Aug 15, 2018Guru - Experienced User
Marc_V wrote:
You may want to visit https://www.netgear.com/about/security/default.aspx and report vulnerabilities :)
It's not a Netgear vulnerability though, it's in vulnerability in some adobe pdf software. It's fairly new (published about a month ago), and all that's happened here is that ClamAV updated their antivirus definitions to detect it. I am a bit confused on what they are detecting though, since as far as I can tell from the published CVE, the vulnerability doesn't affect the on-disk format of the PDF.
Related Content
NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!