A vulnerability in Universal Disk Format (UDF) processing of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a memory overread during UDF file scanning. An attacker could exploit this vulnerability by submitting a crafted file containing UDF content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process, resulting in a DoS condition on the affected software. For a description of this vulnerability, see the .
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade clamav1.4-freshclam-debuginfoUpgrade clamav1.4-lib-debuginfoUpgrade clamd1.4-debuginfoUpgrade clamav1.4-milter-debuginfoUpgrade clamav1.4-freshclamUpgrade clamd1.4Upgrade clamav1.4-docUpgrade clamav1.4-dataUpgrade clamav1.4Upgrade clamav1.4-develUpgrade clamav1.4-filesystemUpgrade clamav1.4-debuginfoUpgrade clamav1.4-milterUpgrade clamav1.4-debugsourceUpgrade clamav1.4-lib | Jul 11, 2025 | Jun 18, 2025 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jun 18, 2025 |
| Debian | — | Upgrade clamavNo solution exists | Jun 20, 2025 | Jun 18, 2025 |
| Freebsd | — | Upgrade clamav | Jun 22, 2025 | Jun 20, 2025 |
| Suse | — | Upgrade clamav-docs-htmlUpgrade clamav-milterUpgrade libclamav12Upgrade libclammspack0Upgrade libfreshclam3Upgrade clamavUpgrade clamav-devel | Jun 27, 2025 | Jun 18, 2025 |
| Ubuntu | — | Upgrade clamavUpgrade clamav (Ubuntu Pro) | Jul 3, 2025 | Jun 18, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub