A vulnerability in the OOXML parsing module in Clam AntiVirus (ClamAV) Software version 0.104.1 and LTS version 0.103.4 and prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper checks that may result in an invalid pointer read. An attacker could exploit this vulnerability by sending a crafted OOXML file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to crash, resulting in a denial of service condition.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade clamav | Aug 22, 2024 | Jan 14, 2022 |
| Amazon_linux_2023 | — | Upgrade clamav-develUpgrade clamav-libUpgrade clamavUpgrade clamdUpgrade clamav-lib-debuginfoUpgrade clamav-filesystemUpgrade clamav-updateUpgrade clamav-debuginfoUpgrade clamd-debuginfoUpgrade clamav-update-debuginfoUpgrade clamav-milter-debuginfoUpgrade clamav-milterUpgrade clamav-debugsourceUpgrade clamav-data | Feb 17, 2025 | Jan 14, 2022 |
| Debian | — | Upgrade clamav | Jul 30, 2024 | Jan 14, 2022 |
| Freebsd | — | Upgrade clamavUpgrade clamav-lts | Nov 4, 2022 | Jan 12, 2022 |
| Gentoo Linux | — | Upgrade app-antivirus/clamav. | Oct 2, 2023 | Jan 14, 2022 |
| Suse | — | Upgrade clamav-openssl1Upgrade clamav-develUpgrade libfreshclam2Upgrade libclamav9Upgrade clamav | Jan 25, 2022 | Jan 14, 2022 |
| Ubuntu | — | Upgrade clamavUpgrade clamav (Ubuntu Pro) | Jan 19, 2022 | Jan 14, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub