On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in CHM file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. For a description of this vulnerability, see the ClamAV blog. This advisory will be updated as additional information becomes available.
CVSS Details
- CVSS 3.1 Base Score: 8.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade clamav | Oct 1, 2024 | May 4, 2022 |
| Amazon_linux | — | Upgrade clamav | Aug 5, 2022 | May 4, 2022 |
| Amazon_linux_2023 | — | Upgrade clamav-milterUpgrade clamav-updateUpgrade clamav-update-debuginfoUpgrade clamav-lib-debuginfoUpgrade clamav-dataUpgrade clamav-debuginfoUpgrade clamav-debugsourceUpgrade clamav-libUpgrade clamav-develUpgrade clamav-milter-debuginfoUpgrade clamavUpgrade clamdUpgrade clamd-debuginfoUpgrade clamav-filesystem | Feb 17, 2025 | May 4, 2022 |
| Debian | — | Upgrade clamav | Jun 6, 2022 | May 4, 2022 |
| Freebsd | — | Upgrade clamav-ltsUpgrade clamav | Nov 4, 2022 | May 19, 2022 |
| Gentoo Linux | — | Upgrade app-antivirus/clamav. | Oct 2, 2023 | May 4, 2022 |
| Suse | — | Upgrade libfreshclam2Upgrade clamav-develUpgrade clamavUpgrade libclamav9 | Oct 26, 2022 | May 4, 2022 |
| Ubuntu | — | Upgrade clamavUpgrade clamav (Ubuntu Pro) | May 18, 2022 | May 4, 2022 |
| Zimbra Collaboration | — | Upgrade Zimbra Collaboration to the latest version | Feb 26, 2025 | May 4, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub