A vulnerability in the email parsing module Clam AntiVirus (ClamAV) Software versions 0.102.0, 0.101.4 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to inefficient MIME parsing routines that result in extremely long scan times of specially formatted email files. An attacker could exploit this vulnerability by sending a crafted email file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to scan the crafted email file indefinitely, resulting in a denial of service condition.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade clamav | Aug 22, 2024 | Jan 15, 2020 |
| Amazon_linux | — | Upgrade clamav | Jan 17, 2020 | Sep 6, 2019 |
| Debian | — | Upgrade clamav | Feb 20, 2020 | Jan 15, 2020 |
| Freebsd | — | Upgrade clamav | Nov 26, 2019 | Nov 25, 2019 |
| Gentoo Linux | — | Upgrade app-antivirus/clamav. | Mar 20, 2020 | Jan 15, 2020 |
| Suse | — | Upgrade libclamav9Upgrade clamav-develUpgrade libfreshclam2Upgrade libclamav7Upgrade libclammspack0Upgrade clamav | Dec 6, 2019 | Sep 6, 2019 |
| Ubuntu | — | Upgrade clamavUpgrade clamav (Ubuntu Pro) | Jan 9, 2020 | Sep 6, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub