USN-5423-1
Dashboard / Vulnerabilities / USN-5423-1
USN-5423-1
Summary: clamav vulnerabilities
Details: Michał Dardas discovered that ClamAV incorrectly handled parsing CHM files. A remote attacker could possibly use this issue to cause ClamAV to stop responding, resulting in a denial of service. (CVE-2022-20770) Michał Dardas discovered that ClamAV incorrectly handled parsing TIFF files. A remote attacker could possibly use this issue to cause ClamAV to stop responding, resulting in a denial of service. (CVE-2022-20771) Michał Dardas discovered that ClamAV incorrectly handled parsing HTML files. A remote attacker could possibly use this issue to cause ClamAV to consume resources, resulting in a denial of service. (CVE-2022-20785) Michał Dardas discovered that ClamAV incorrectly handled loading the signature database. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2022-20792) Alexander Patrakov and Antoine Gatineau discovered that ClamAV incorrectly handled the scan verdict cache check. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service, or possibly execute arbitrary code.(CVE-2022-20796)
References: https://ubuntu.com/security/notices/USN-5423-1, https://ubuntu.com/security/CVE-2022-20770, https://ubuntu.com/security/CVE-2022-20771, https://ubuntu.com/security/CVE-2022-20785, https://ubuntu.com/security/CVE-2022-20792, https://ubuntu.com/security/CVE-2022-20796
Affected packages
Package
Name: clamav
Purl: pkg:deb/ubuntu/[email protected]+dfsg-0ubuntu0.18.04.1?arch=source&distro=bionic
Affected ranges
Type: ECOSYSTEM
Events:
