ClamAV versions prior to 0.101.2 are susceptible to a denial of service (DoS) vulnerability. An out-of-bounds heap read condition may occur when scanning PE files. An example is Windows EXE and DLL files that have been packed using Aspack as a result of inadequate bound-checking.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade clamav | Nov 5, 2019 | Nov 5, 2019 |
| Amazon_linux | — | Upgrade clamav | May 21, 2019 | Mar 29, 2019 |
| Debian | — | Upgrade clamav | Apr 23, 2019 | Apr 23, 2019 |
| Freebsd | — | Upgrade clamav | Apr 5, 2019 | Apr 5, 2019 |
| Gentoo Linux | — | Upgrade app-antivirus/clamav. | Apr 12, 2019 | Apr 8, 2019 |
| Suse | — | Upgrade libclammspack0Upgrade libclamav9Upgrade clamav-develUpgrade libfreshclam2Upgrade libclamav7Upgrade clamav | Apr 10, 2019 | Mar 29, 2019 |
| Ubuntu | — | Upgrade clamav | Apr 12, 2019 | Mar 29, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub