๐Ÿ” CVE Alert

CVE-2022-20803

HIGH 8.6

ClamAV Double-free Vulnerability in the OLE2 File Parser

CVSS Score
8.6
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability in the OLE2 file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device.The vulnerability is due to incorrect use of the realloc function that may result in a double-free. An attacker could exploit this vulnerability by submitting a crafted OLE2 file to be scanned by ClamAV on the affected device. An exploit could allow the attacker to cause the ClamAV scanning process to crash, resulting in a denial of service condition.

CWE CWE-415
Vendor cisco
Product clamav
Ecosystems
Industries
NetworkingTelecommunications
Published Feb 17, 2023
Last Updated Oct 28, 2024
Stay Ahead of the Next One

Get instant alerts for cisco clamav

Be the first to know when new high vulnerabilities affecting cisco clamav are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

Cisco / ClamAV
0.104.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
blog.clamav.net: https://blog.clamav.net/2022/05/clamav-01050-01043-01036-released.html security.gentoo.org: https://security.gentoo.org/glsa/202310-01