On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in HTML file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. For a description of this vulnerability, see the ClamAV blog. This advisory will be updated as additional information becomes available.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade clamav | Oct 1, 2024 | May 4, 2022 |
| Amazon_linux | — | Upgrade clamav | Aug 5, 2022 | May 4, 2022 |
| Amazon_linux_2023 | — | Upgrade clamavUpgrade clamav-libUpgrade clamav-develUpgrade clamdUpgrade clamav-filesystemUpgrade clamav-milterUpgrade clamav-debuginfoUpgrade clamav-debugsourceUpgrade clamav-update-debuginfoUpgrade clamav-lib-debuginfoUpgrade clamav-dataUpgrade clamav-updateUpgrade clamd-debuginfoUpgrade clamav-milter-debuginfo | Feb 17, 2025 | May 4, 2022 |
| Debian | — | Upgrade clamav | Jun 6, 2022 | May 4, 2022 |
| Freebsd | — | Upgrade clamavUpgrade clamav-lts | Nov 4, 2022 | May 19, 2022 |
| Gentoo Linux | — | Upgrade app-antivirus/clamav. | Oct 2, 2023 | May 4, 2022 |
| Suse | — | Upgrade libfreshclam2Upgrade clamavUpgrade libclamav9Upgrade clamav-devel | Oct 26, 2022 | May 4, 2022 |
| Ubuntu | — | Upgrade clamav (Ubuntu Pro)Upgrade clamav | May 18, 2022 | May 4, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub