USN-6636-1
Dashboard / Vulnerabilities / USN-6636-1
USN-6636-1
Summary: clamav vulnerabilities
Details: It was discovered that ClamAV incorrectly handled parsing certain OLE2 files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2024-20290) Amit Schendel discovered that the ClamAV ClamD service incorrectly handled the VirusEvent feature. An attacker able to connect to ClamD could possibly use this issue to execute arbitrary code. (CVE-2024-20328)
References: https://ubuntu.com/security/notices/USN-6636-1, https://ubuntu.com/security/CVE-2024-20290, https://ubuntu.com/security/CVE-2024-20328
Affected packages
Package
Name: clamav
Purl: pkg:deb/ubuntu/[email protected]+dfsg-0ubuntu0.23.10.1?arch=source&distro=mantic
Affected ranges
Type: ECOSYSTEM
Events:
