On May 4, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in Clam AntiVirus (ClamAV) versions 0.103.4, 0.103.5, 0.104.1, and 0.104.2 could allow an authenticated, local attacker to cause a denial of service condition on an affected device. For a description of this vulnerability, see the ClamAV blog.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade clamav | Oct 1, 2024 | May 4, 2022 |
| Amazon_linux | — | Upgrade clamav | Aug 5, 2022 | May 4, 2022 |
| Amazon_linux_2023 | — | Upgrade clamdUpgrade clamav-milter-debuginfoUpgrade clamav-lib-debuginfoUpgrade clamav-develUpgrade clamav-libUpgrade clamav-debuginfoUpgrade clamav-filesystemUpgrade clamav-updateUpgrade clamavUpgrade clamd-debuginfoUpgrade clamav-milterUpgrade clamav-update-debuginfoUpgrade clamav-dataUpgrade clamav-debugsource | Feb 17, 2025 | May 4, 2022 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | May 4, 2022 |
| Debian | — | Upgrade clamav | Jun 6, 2022 | May 4, 2022 |
| Freebsd | — | Upgrade clamav-ltsUpgrade clamav | Nov 4, 2022 | May 19, 2022 |
| Gentoo Linux | — | Upgrade app-antivirus/clamav. | Oct 2, 2023 | May 4, 2022 |
| Suse | — | Upgrade clamav-develUpgrade libfreshclam2Upgrade libclamav9Upgrade clamav | Oct 26, 2022 | May 4, 2022 |
| Ubuntu | — | Upgrade clamav (Ubuntu Pro)Upgrade clamav | May 18, 2022 | May 4, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub