A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a heap buffer overflow read. An attacker could exploit this vulnerability by sending a crafted ARJ file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process crash, resulting in a denial of service condition.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade clamav | Aug 22, 2024 | May 13, 2020 |
| Amazon_linux | — | Upgrade clamav | Sep 17, 2020 | May 13, 2020 |
| Debian | — | Upgrade clamav | May 21, 2020 | May 13, 2020 |
| Freebsd | — | Upgrade clamav | Jul 16, 2020 | Jul 16, 2020 |
| Gentoo Linux | — | Upgrade app-antivirus/clamav. | Jul 28, 2020 | May 13, 2020 |
| Suse | — | Upgrade clamavUpgrade libfreshclam2Upgrade clamav-develUpgrade libclamav9 | Dec 11, 2020 | May 13, 2020 |
| Ubuntu | — | Upgrade clamav (Ubuntu Pro)Upgrade clamav | May 22, 2020 | May 13, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub