A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an integer underflow in a bounds check that allows for a heap buffer overflow read. An attacker could exploit this vulnerability by submitting a crafted file containing OLE2 content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process, resulting in a DoS condition on the affected software. For a description of this vulnerability, see the . Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-clamav | Aug 8, 2025 | Jan 22, 2025 | |
| Amazon_linux_2023 | amazon-linux-2023-upgrade-clamav1-4amazon-linux-2023-upgrade-clamav1-4-dataamazon-linux-2023-upgrade-clamav1-4-debuginfoamazon-linux-2023-upgrade-clamav1-4-debugsourceamazon-linux-2023-upgrade-clamav1-4-develamazon-linux-2023-upgrade-clamav1-4-docamazon-linux-2023-upgrade-clamav1-4-filesystemamazon-linux-2023-upgrade-clamav1-4-freshclamamazon-linux-2023-upgrade-clamav1-4-freshclam-debuginfoamazon-linux-2023-upgrade-clamav1-4-libamazon-linux-2023-upgrade-clamav1-4-lib-debuginfoamazon-linux-2023-upgrade-clamav1-4-milteramazon-linux-2023-upgrade-clamav1-4-milter-debuginfoamazon-linux-2023-upgrade-clamd1-4amazon-linux-2023-upgrade-clamd1-4-debuginfo | Mar 10, 2025 | Jan 22, 2025 | |
| Debian | debian-upgrade-clamav | May 15, 2025 | Jan 22, 2025 | |
| Freebsd | freebsd-upgrade-package-clamavfreebsd-upgrade-package-clamav-lts | Jan 24, 2025 | Jan 23, 2025 | |
| Suse | — | suse-upgrade-clamavsuse-upgrade-clamav-develsuse-upgrade-clamav-docs-htmlsuse-upgrade-clamav-miltersuse-upgrade-libclamav12suse-upgrade-libclammspack0suse-upgrade-libfreshclam3 | Feb 5, 2025 | Jan 22, 2025 |
| Ubuntu | ubuntu-upgrade-clamav | Jan 30, 2025 | Jan 22, 2025 | |
| Zimbra Collaboration | zimbra-collaboration-upgrade-latest | May 19, 2025 | Jan 22, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub