A vulnerability in Universal Disk Format (UDF) processing of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a memory overread during UDF file scanning. An attacker could exploit this vulnerability by submitting a crafted file containing UDF content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process, resulting in a DoS condition on the affected software. For a description of this vulnerability, see the .
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade clamav1.4-docUpgrade clamd1.4Upgrade clamav1.4-lib-debuginfoUpgrade clamav1.4-freshclamUpgrade clamav1.4-freshclam-debuginfoUpgrade clamav1.4-milter-debuginfoUpgrade clamd1.4-debuginfoUpgrade clamav1.4Upgrade clamav1.4-dataUpgrade clamav1.4-libUpgrade clamav1.4-debuginfoUpgrade clamav1.4-milterUpgrade clamav1.4-develUpgrade clamav1.4-filesystemUpgrade clamav1.4-debugsource | Jul 11, 2025 | Jun 18, 2025 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jun 18, 2025 |
| Debian | — | Upgrade clamavNo solution exists | Jun 20, 2025 | Jun 18, 2025 |
| Freebsd | — | Upgrade clamav | Jun 22, 2025 | Jun 20, 2025 |
| Suse | — | Upgrade libclamav12Upgrade clamav-docs-htmlUpgrade clamav-milterUpgrade libfreshclam3Upgrade libclammspack0Upgrade clamavUpgrade clamav-devel | Jun 27, 2025 | Jun 18, 2025 |
| Ubuntu | — | Upgrade clamavUpgrade clamav (Ubuntu Pro) | Jul 3, 2025 | Jun 18, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub