On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in the TIFF file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. For a description of this vulnerability, see the ClamAV blog. This advisory will be updated as additional information becomes available.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade clamav | Oct 1, 2024 | May 4, 2022 |
| Amazon_linux | — | Upgrade clamav | Aug 5, 2022 | May 4, 2022 |
| Amazon_linux_2023 | — | Upgrade clamav-debuginfoUpgrade clamav-update-debuginfoUpgrade clamav-debugsourceUpgrade clamav-updateUpgrade clamdUpgrade clamav-dataUpgrade clamav-lib-debuginfoUpgrade clamav-milter-debuginfoUpgrade clamav-milterUpgrade clamav-develUpgrade clamav-filesystemUpgrade clamd-debuginfoUpgrade clamavUpgrade clamav-lib | Feb 17, 2025 | May 4, 2022 |
| Debian | — | Upgrade clamav | Jun 6, 2022 | May 4, 2022 |
| Freebsd | — | Upgrade clamavUpgrade clamav-lts | Nov 4, 2022 | May 19, 2022 |
| Gentoo Linux | — | Upgrade app-antivirus/clamav. | Oct 2, 2023 | May 4, 2022 |
| Suse | — | Upgrade clamavUpgrade libclamav9Upgrade clamav-develUpgrade libfreshclam2 | Oct 26, 2022 | May 4, 2022 |
| Ubuntu | — | Upgrade clamavUpgrade clamav (Ubuntu Pro) | May 18, 2022 | May 4, 2022 |
| Zimbra Collaboration | — | Upgrade Zimbra Collaboration to the latest version | Feb 26, 2025 | May 4, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub