On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in CHM file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. For a description of this vulnerability, see the ClamAV blog. This advisory will be updated as additional information becomes available.
CVSS Details
- CVSS 3.1 Base Score: 8.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade clamav | Oct 1, 2024 | May 4, 2022 |
| Amazon_linux | — | Upgrade clamav | Aug 5, 2022 | May 4, 2022 |
| Amazon_linux_2023 | — | Upgrade clamav-updateUpgrade clamav-debugsourceUpgrade clamav-milterUpgrade clamav-update-debuginfoUpgrade clamav-debuginfoUpgrade clamav-dataUpgrade clamav-lib-debuginfoUpgrade clamav-libUpgrade clamd-debuginfoUpgrade clamav-develUpgrade clamav-filesystemUpgrade clamavUpgrade clamdUpgrade clamav-milter-debuginfo | Feb 17, 2025 | May 4, 2022 |
| Debian | — | Upgrade clamav | Jun 6, 2022 | May 4, 2022 |
| Freebsd | — | Upgrade clamavUpgrade clamav-lts | Nov 4, 2022 | May 19, 2022 |
| Gentoo Linux | — | Upgrade app-antivirus/clamav. | Oct 2, 2023 | May 4, 2022 |
| Suse | — | Upgrade libfreshclam2Upgrade libclamav9Upgrade clamavUpgrade clamav-devel | Oct 26, 2022 | May 4, 2022 |
| Ubuntu | — | Upgrade clamavUpgrade clamav (Ubuntu Pro) | May 18, 2022 | May 4, 2022 |
| Zimbra Collaboration | — | Upgrade Zimbra Collaboration to the latest version | Feb 26, 2025 | May 4, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub