A vulnerability in the EGG archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.0 - 0.102.3 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a null pointer dereference. An attacker could exploit this vulnerability by sending a crafted EGG file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process crash, resulting in a denial of service condition.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade clamav | Jan 4, 2021 | Jul 20, 2020 |
| Amazon_linux | — | Upgrade clamav | Sep 17, 2020 | Jul 16, 2020 |
| Debian | — | Upgrade clamav | Aug 7, 2020 | Jul 20, 2020 |
| Freebsd | — | Upgrade clamav | Jul 18, 2020 | Jul 16, 2020 |
| Gentoo Linux | — | Upgrade app-antivirus/clamav. | Jul 28, 2020 | Jul 20, 2020 |
| Suse | — | Upgrade libfreshclam2Upgrade libclamav9Upgrade clamav-develUpgrade clamav | Dec 11, 2020 | Jul 16, 2020 |
| Ubuntu | — | Upgrade clamavUpgrade clamav (Ubuntu Pro) | Aug 5, 2020 | Jul 16, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub