vulnerability

FreeBSD: VID-B2407DB1-D79F-11EC-A15F-589CFC0F81B0 (CVE-2022-20803): clamav -- Multiple vulnerabilities

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
2022-05-04
Added
2022-11-04
Modified
2025-01-28

Description

Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.


From VID-B2407DB1-D79F-11EC-A15F-589CFC0F81B0:




The ClamAV project reports:



Fixed a possible double-free vulnerability in the OLE2 file


parser. Issue affects versions 0.104.0 through 0.104.2. Issue


identified by OSS-Fuzz.


Fixed a possible infinite loop vulnerability in the CHM file


parser. Issue affects versions 0.104.0 through 0.104.2 and LTS


version 0.103.5 and prior versions. Thank you to Michał Dardas


for reporting this issue.


Fixed a possible NULL-pointer dereference crash in the scan


verdict cache check. Issue affects versions 0.103.4, 0.103.5,


0.104.1, and 0.104.2. Thank you to Alexander Patrakov and


Antoine Gatineau for reporting this issue.


Fixed a possible infinite loop vulnerability in the TIFF file


parser. Issue affects versions 0.104.0 through 0.104.2 and LTS


version 0.103.5 and prior versions. The issue only occurs if the


"--alert-broken-media" ClamScan option is enabled. For ClamD,


the affected option is "AlertBrokenMedia yes", and for libclamav


it is the "CL_SCAN_HEURISTIC_BROKEN_MEDIA" scan option. Thank


you to Michał Dardas for reporting this issue.


Fixed a possible memory leak in the HTML file parser /


Javascript normalizer. Issue affects versions 0.104.0 through


0.104.2 and LTS version 0.103.5 and prior versions. Thank you to


Michał Dardas for reporting this issue.


Fixed a possible multi-byte heap buffer overflow write


vulnerability in the signature database load module. The fix was


to update the vendored regex library to the latest version.


Issue affects versions 0.104.0 through 0.104.2 and LTS version


0.103.5 and prior versions. Thank you to Michał Dardas for


reporting this issue.




Solution(s)

freebsd-upgrade-package-clamavfreebsd-upgrade-package-clamav-lts
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.