This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Clamav First view 2008-09-10
Product Clamav Last view 2024-09-04
Version 0.93.1 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:clamav:clamav

Activity : Overall

Related : CVE

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
  Date Alert Description
6.1 2024-09-04 CVE-2024-20506

A vulnerability in the ClamD service module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2.x versions, 1.0.6 and prior versions, all 0.105.x versions, all 0.104.x versions, and 0.103.11 and all prior versions could allow an authenticated, local attacker to corrupt critical system files.

The vulnerability is due to allowing the ClamD process to write to its log file while privileged without checking if the logfile has been replaced with a symbolic link. An attacker could exploit this vulnerability if they replace the ClamD log file with a symlink to a critical system file and then find a way to restart the ClamD process. An exploit could allow the attacker to corrupt a critical system file by appending ClamD log messages after restart.

7.5 2024-09-04 CVE-2024-20505

A vulnerability in the PDF parsing module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2.x versions, 1.0.6 and prior versions, all 0.105.x versions, all 0.104.x versions, and 0.103.11 and all prior versions could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

The vulnerability is due to an out of bounds read. An attacker could exploit this vulnerability by submitting a crafted PDF file to be scanned by ClamAV on an affected device. An exploit could allow the attacker to terminate the scanning process.

5.3 2023-03-01 CVE-2023-20052

On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed:

A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to access sensitive information on an affected device.

This vulnerability is due to enabling XML entity substitution that may result in XML external entity injection. An attacker could exploit this vulnerability by submitting a crafted DMG file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to leak bytes from any file that may be read by the ClamAV scanning process.

9.8 2023-03-01 CVE-2023-20032

On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed:

A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to execute arbitrary code.

This vulnerability is due to a missing buffer size check that may result in a heap buffer overflow write. An attacker could exploit this vulnerability by submitting a crafted HFS+ partition file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to execute arbitrary code with the privileges of the ClamAV scanning process, or else crash the process, resulting in a denial of service (DoS) condition.

For a description of this vulnerability, see the ClamAV blog ["https://blog.clamav.net/"].

7.5 2023-02-17 CVE-2022-20803

A vulnerability in the OLE2 file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device.The vulnerability is due to incorrect use of the realloc function that may result in a double-free. An attacker could exploit this vulnerability by submitting a crafted OLE2 file to be scanned by ClamAV on the affected device. An exploit could allow the attacker to cause the ClamAV scanning process to crash, resulting in a denial of service condition.

7.8 2022-08-10 CVE-2022-20792

A vulnerability in the regex module used by the signature database load module of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior versions could allow an authenticated, local attacker to crash ClamAV at database load time, and possibly gain code execution. The vulnerability is due to improper bounds checking that may result in a multi-byte heap buffer overwflow write. An attacker could exploit this vulnerability by placing a crafted CDB ClamAV signature database file in the ClamAV database directory. An exploit could allow the attacker to run code as the clamav user.

7.5 2022-05-04 CVE-2022-20785

On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in HTML file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. For a description of this vulnerability, see the ClamAV blog. This advisory will be updated as additional information becomes available.

7.5 2022-05-04 CVE-2022-20771

On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in the TIFF file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. For a description of this vulnerability, see the ClamAV blog. This advisory will be updated as additional information becomes available.

7.5 2022-05-04 CVE-2022-20770

On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in CHM file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. For a description of this vulnerability, see the ClamAV blog. This advisory will be updated as additional information becomes available.

7.5 2022-01-14 CVE-2022-20698

A vulnerability in the OOXML parsing module in Clam AntiVirus (ClamAV) Software version 0.104.1 and LTS version 0.103.4 and prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper checks that may result in an invalid pointer read. An attacker could exploit this vulnerability by sending a crafted OOXML file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to crash, resulting in a denial of service condition.

7.5 2021-04-08 CVE-2021-1405

A vulnerability in the email parsing module in Clam AntiVirus (ClamAV) Software version 0.103.1 and all prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper variable initialization that may result in an NULL pointer read. An attacker could exploit this vulnerability by sending a crafted email to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process crash, resulting in a denial of service condition.

5.5 2021-03-19 CVE-2021-27506

The ClamAV Engine (version 0.103.1 and below) component embedded in Storsmshield Network Security (SNS) is subject to DoS in case of parsing of malformed png files. This affect Netasq versions 9.1.0 to 9.1.11 and SNS versions 1.0.0 to 4.2.0. This issue is fixed in SNS 3.7.19, 3.11.7 and 4.2.1.

7.5 2020-07-20 CVE-2020-3481

A vulnerability in the EGG archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.0 - 0.102.3 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a null pointer dereference. An attacker could exploit this vulnerability by sending a crafted EGG file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process crash, resulting in a denial of service condition.

6.5 2020-01-15 CVE-2019-15961

A vulnerability in the email parsing module Clam AntiVirus (ClamAV) Software versions 0.102.0, 0.101.4 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to inefficient MIME parsing routines that result in extremely long scan times of specially formatted email files. An attacker could exploit this vulnerability by sending a crafted email file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to scan the crafted email file indefinitely, resulting in a denial of service condition.

7.5 2019-11-15 CVE-2013-7089

ClamAV before 0.97.7: dbg_printhex possible information leak

9.8 2019-11-15 CVE-2013-7088

ClamAV before 0.97.7 has buffer overflow in the libclamav component

9.8 2019-11-15 CVE-2013-7087

ClamAV before 0.97.7 has WWPack corrupt heap memory

9.8 2019-11-06 CVE-2007-0899

There is a possible heap overflow in libclamav/fsg.c before 0.100.0.

7.5 2019-11-05 CVE-2019-1789

ClamAV versions prior to 0.101.2 are susceptible to a denial of service (DoS) vulnerability. An out-of-bounds heap read condition may occur when scanning PE files. An example is Windows EXE and DLL files that have been packed using Aspack as a result of inadequate bound-checking.

7.5 2019-11-05 CVE-2019-12625

ClamAV versions prior to 0.101.3 are susceptible to a zip bomb vulnerability where an unauthenticated attacker can cause a denial of service condition by sending crafted messages to an affected system.

5.5 2019-04-08 CVE-2019-1798

A vulnerability in the Portable Executable (PE) file scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a lack of proper input and validation checking mechanisms for PE files sent an affected device. An attacker could exploit this vulnerability by sending malformed PE files to the device running an affected version ClamAV Software. An exploit could allow the attacker to cause an out-of-bounds read condition, resulting in a crash that could result in a denial of service condition on an affected device.

5.5 2019-04-08 CVE-2019-1788

A vulnerability in the Object Linking & Embedding (OLE2) file scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a lack of proper input and validation checking mechanisms for OLE2 files sent an affected device. An attacker could exploit this vulnerability by sending malformed OLE2 files to the device running an affected version ClamAV Software. An exploit could allow the attacker to cause an out-of-bounds write condition, resulting in a crash that could result in a denial of service condition on an affected device.

5.5 2019-04-08 CVE-2019-1787

A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a lack of proper data handling mechanisms within the device buffer while indexing remaining file data on an affected device. An attacker could exploit this vulnerability by sending crafted PDF files to an affected device. A successful exploit could allow the attacker to cause a heap buffer out-of-bounds read condition, resulting in a crash that could result in a denial of service condition on an affected device.

5.5 2018-10-15 CVE-2018-15378

A vulnerability in ClamAV versions prior to 0.100.2 could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to an error related to the MEW unpacker within the "unmew11()" function (libclamav/mew.c), which can be exploited to trigger an invalid read memory access via a specially crafted EXE file.

3.3 2018-07-16 CVE-2018-0361

ClamAV before 0.100.1 lacks a PDF object length check, resulting in an unreasonably long time to parse a relatively small file.

CWE : Common Weakness Enumeration

%idName
17% (10) CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer
16% (9) CWE-125 Out-of-bounds Read
10% (6) CWE-399 Resource Management Errors
8% (5) CWE-189 Numeric Errors
7% (4) CWE-787 Out-of-bounds Write
7% (4) CWE-20 Improper Input Validation
3% (2) CWE-476 NULL Pointer Dereference
3% (2) CWE-401 Failure to Release Memory Before Removing Last Reference ('Memory L...
3% (2) CWE-284 Access Control (Authorization) Issues
3% (2) CWE-200 Information Exposure
3% (2) CWE-17 Code
1% (1) CWE-776 Unrestricted Recursive Entity References in DTDs ('XML Bomb')
1% (1) CWE-754 Improper Check for Unusual or Exceptional Conditions
1% (1) CWE-416 Use After Free
1% (1) CWE-415 Double Free
1% (1) CWE-404 Improper Resource Shutdown or Release
1% (1) CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
1% (1) CWE-190 Integer Overflow or Wraparound
1% (1) CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflo...

Open Source Vulnerability Database (OSVDB)

id Description
76785 ClamAV Multiple Function Recursion Level File Handling Remote DoS
74181 ClamAV clamd libclamav/matcher-hash.c cli_hm_scan() Function Crafted Message ...
70937 ClamAV vba_extract.c vba_read_project_strings() Function Double-free Arbitrar...
69656 ClamAV libclamav pdf.c PDF File Handling DoS (2010-4479)
69612 ClamAV libclamav pe_icons.c icon_cb() Function Off-by-one Memory Corruption
69611 ClamAV libclamav pdf.c PDF File Handling DoS (2010-4260)
68302 ClamAV pdf.c find_stream_bounds Function Crafted PDF File Handling Overflow
64774 ClamAV libclamav/pdf.c cli_pdf() Function PDF File Handling DoS
63861 ClamAV Malformed CAB File Scanning Bypass
63818 ClamAV libclamav/mspack.c qtm_decompress Function Crafted CAB Archive DoS
53603 ClamAV libclamav/phishcheck.c cli_url_canon() Function URL Handling Overflow
53602 ClamAV Malformed UPack Packed File Handling DoS
53598 ClamAV --detect-broken Option PE File Handling DoS
53597 ClamAV RAR Archive Invalid Uncompressed Size Field Scan Bypass
53461 ClamAV libclamav/untar.c clamd / clamscan Infinite Loop DoS
51963 ClamAV LZH Archive Handling DoS
50772 ClamAV HTML Document MZ Header Multiple Filename Modification Malware Detecti...
48239 ClamAV error path File Descriptor Leak Multiple Unspecified Issue
48238 ClamAV freshclam/manager.c error path Unspecified Memory Consumption DoS
48237 ClamAV libclamav Unspecified Memory Exhaustion DoS

OpenVAS Exploits

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
id Description
2012-07-16 Name : Fedora Update for clamav FEDORA-2012-9577
File : nvt/gb_fedora_2012_9577_clamav_fc16.nasl
2012-04-02 Name : Fedora Update for clamav FEDORA-2011-15033
File : nvt/gb_fedora_2011_15033_clamav_fc16.nasl
2012-02-12 Name : Gentoo Security Advisory GLSA 201110-20 (Clam AntiVirus)
File : nvt/glsa_201110_20.nasl
2011-11-22 Name : ClamAV Recursion Level Handling Denial of Service Vulnerability (Windows)
File : nvt/secpod_clamav_recursion_dos_vuln_win.nasl
2011-11-11 Name : Ubuntu Update for clamav USN-1258-1
File : nvt/gb_ubuntu_USN_1258_1.nasl
2011-11-11 Name : Fedora Update for clamav FEDORA-2011-15119
File : nvt/gb_fedora_2011_15119_clamav_fc15.nasl
2011-11-11 Name : Fedora Update for clamav FEDORA-2011-15076
File : nvt/gb_fedora_2011_15076_clamav_fc14.nasl
2011-08-29 Name : ClamAV Hash Manager Off-By-One Denial of Service Vulnerability (Win)
File : nvt/secpod_clamav_hash_manager_dos_vuln_win.nasl
2011-08-26 Name : Mac OS X v10.6.6 Multiple Vulnerabilities (2011-001)
File : nvt/secpod_macosx_su11-001.nasl
2011-08-19 Name : Fedora Update for clamav FEDORA-2011-10090
File : nvt/gb_fedora_2011_10090_clamav_fc15.nasl
2011-08-19 Name : Fedora Update for clamav FEDORA-2011-10053
File : nvt/gb_fedora_2011_10053_clamav_fc14.nasl
2011-08-18 Name : Mandriva Update for clamav MDVSA-2011:122 (clamav)
File : nvt/gb_mandriva_MDVSA_2011_122.nasl
2011-08-02 Name : Ubuntu Update for clamav USN-1179-1
File : nvt/gb_ubuntu_USN_1179_1.nasl
2011-03-15 Name : Fedora Update for clamav FEDORA-2011-2743
File : nvt/gb_fedora_2011_2743_clamav_fc14.nasl
2011-03-15 Name : Fedora Update for clamav FEDORA-2011-2741
File : nvt/gb_fedora_2011_2741_clamav_fc13.nasl
2011-03-09 Name : Gentoo Security Advisory GLSA 201009-06 (clamav)
File : nvt/glsa_201009_06.nasl
2011-03-07 Name : Ubuntu Update for clamav vulnerability USN-1076-1
File : nvt/gb_ubuntu_USN_1076_1.nasl
2011-02-22 Name : ClamAV 'vba_read_project_strings()' Double Free Memory Corruption Vulnerability
File : nvt/gb_clamav_46470.nasl
2010-12-28 Name : Fedora Update for clamav FEDORA-2010-18564
File : nvt/gb_fedora_2010_18564_clamav_fc13.nasl
2010-12-23 Name : Mandriva Update for clamav MDVSA-2010:249 (clamav)
File : nvt/gb_mandriva_MDVSA_2010_249.nasl
2010-12-23 Name : Fedora Update for clamav FEDORA-2010-18568
File : nvt/gb_fedora_2010_18568_clamav_fc14.nasl
2010-12-23 Name : Ubuntu Update for clamav vulnerabilities USN-1031-1
File : nvt/gb_ubuntu_USN_1031_1.nasl
2010-12-02 Name : ClamAV Prior to 0.96.5 Multiple Vulnerabilities
File : nvt/gb_clamav_45152.nasl
2010-12-02 Name : Fedora Update for clamav FEDORA-2010-13012
File : nvt/gb_fedora_2010_13012_clamav_fc14.nasl
2010-10-07 Name : ClamAV 'find_stream_bounds()' function Buffer Overflow Vulnerability
File : nvt/gb_clamav_pdf_bof_vuln_lin.nasl

Information Assurance Vulnerability Management (IAVM)

id Description
2013-A-0179 Apple Mac OS X Security Update 2013-004
Severity: Category I - VMSKEY: V0040373

Nessus® Vulnerability Scanner

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
id Description
2019-01-14 Name: The remote Amazon Linux AMI host is missing a security update.
File: ala_ALAS-2019-1146.nasl - Type: ACT_GATHER_INFO
2019-01-03 Name: The remote Fedora host is missing a security update.
File: fedora_2018-847fe2ed61.nasl - Type: ACT_GATHER_INFO
2019-01-03 Name: The remote Fedora host is missing a security update.
File: fedora_2018-eff94da132.nasl - Type: ACT_GATHER_INFO
2018-10-25 Name: The remote Debian host is missing a security update.
File: debian_DLA-1553.nasl - Type: ACT_GATHER_INFO
2018-10-17 Name: The remote Fedora host is missing a security update.
File: fedora_2018-1fc39f2d13.nasl - Type: ACT_GATHER_INFO
2018-10-04 Name: The remote FreeBSD host is missing a security-related update.
File: freebsd_pkg_8b812395c73911e8ab5b9c5c8e75236a.nasl - Type: ACT_GATHER_INFO
2018-08-22 Name: The remote Debian host is missing a security update.
File: debian_DLA-1461.nasl - Type: ACT_GATHER_INFO
2018-08-03 Name: The antivirus service running on the remote host is affected by multiple vuln...
File: clamav_0_100_1.nasl - Type: ACT_GATHER_INFO
2018-07-10 Name: The remote FreeBSD host is missing a security-related update.
File: freebsd_pkg_d1e9d8c5839b11e896109c5c8e75236a.nasl - Type: ACT_GATHER_INFO
2018-04-23 Name: The remote Gentoo host is missing one or more security-related patches.
File: gentoo_GLSA-201804-16.nasl - Type: ACT_GATHER_INFO
2018-03-27 Name: The remote Amazon Linux AMI host is missing a security update.
File: ala_ALAS-2018-976.nasl - Type: ACT_GATHER_INFO
2018-03-19 Name: The remote Debian host is missing a security update.
File: debian_DLA-1307.nasl - Type: ACT_GATHER_INFO
2018-03-14 Name: The remote Fedora host is missing a security update.
File: fedora_2018-d2b08aa37f.nasl - Type: ACT_GATHER_INFO
2018-03-07 Name: The remote Fedora host is missing a security update.
File: fedora_2018-602b5345fa.nasl - Type: ACT_GATHER_INFO
2018-02-22 Name: The remote Amazon Linux AMI host is missing a security update.
File: ala_ALAS-2018-958.nasl - Type: ACT_GATHER_INFO
2018-02-07 Name: The remote Fedora host is missing a security update.
File: fedora_2018-958b22c73f.nasl - Type: ACT_GATHER_INFO
2018-02-06 Name: The antivirus service running on the remote host is affected by multiple deni...
File: clamav_0_99_3.nasl - Type: ACT_GATHER_INFO
2018-01-30 Name: The remote Fedora host is missing a security update.
File: fedora_2018-cb339851e7.nasl - Type: ACT_GATHER_INFO
2018-01-29 Name: The remote Debian host is missing a security update.
File: debian_DLA-1261.nasl - Type: ACT_GATHER_INFO
2018-01-29 Name: The remote FreeBSD host is missing a security-related update.
File: freebsd_pkg_b464f61b84c74e1c8ad46cf9efffd025.nasl - Type: ACT_GATHER_INFO
2018-01-29 Name: The remote Gentoo host is missing one or more security-related patches.
File: gentoo_GLSA-201801-19.nasl - Type: ACT_GATHER_INFO
2016-10-06 Name: The antivirus service running on the remote host is affected by multiple deni...
File: clamav_0_99_2.nasl - Type: ACT_GATHER_INFO
2016-09-29 Name: The remote Ubuntu host is missing a security-related patch.
File: ubuntu_USN-3093-1.nasl - Type: ACT_GATHER_INFO
2016-01-04 Name: The remote Gentoo host is missing one or more security-related patches.
File: gentoo_GLSA-201512-08.nasl - Type: ACT_GATHER_INFO
2015-06-04 Name: The remote Amazon Linux AMI host is missing a security update.
File: ala_ALAS-2015-537.nasl - Type: ACT_GATHER_INFO