A vulnerability in Universal Disk Format (UDF) processing of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a memory overread during UDF file scanning. An attacker could exploit this vulnerability by submitting a crafted file containing UDF content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process, resulting in a DoS condition on the affected software. For a description of this vulnerability, see the .
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade clamav1.4-libUpgrade clamav1.4-milterUpgrade clamav1.4-develUpgrade clamav1.4-debuginfoUpgrade clamav1.4-filesystemUpgrade clamav1.4-debugsourceUpgrade clamd1.4Upgrade clamav1.4Upgrade clamav1.4-dataUpgrade clamav1.4-milter-debuginfoUpgrade clamav1.4-freshclam-debuginfoUpgrade clamav1.4-lib-debuginfoUpgrade clamd1.4-debuginfoUpgrade clamav1.4-docUpgrade clamav1.4-freshclam | Jul 11, 2025 | Jun 18, 2025 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jun 18, 2025 |
| Debian | — | No solution existsUpgrade clamav | Jun 20, 2025 | Jun 18, 2025 |
| Freebsd | — | Upgrade clamav | Jun 22, 2025 | Jun 20, 2025 |
| Suse | — | Upgrade clamav-docs-htmlUpgrade libclamav12Upgrade clamav-milterUpgrade libfreshclam3Upgrade clamav-develUpgrade clamavUpgrade libclammspack0 | Jun 27, 2025 | Jun 18, 2025 |
| Ubuntu | — | Upgrade clamav (Ubuntu Pro)Upgrade clamav | Jul 3, 2025 | Jun 18, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub