CVE-2020-3123
A vulnerability in the Data-Loss-Prevention (DLP) module in Clam AntiVirus (ClamAV) Software versions 0.102.1 and 0.102.0 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.60%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability in the Data-Loss-Prevention (DLP) module in Clam AntiVirus (ClamAV) Software versions 0.102.1 and 0.102.0 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to an out-of-bounds read affecting users that have enabled the optional DLP feature. An attacker could exploit this vulnerability by sending a crafted email file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process crash, resulting in a denial of service condition.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 2.60% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- clamav/clamav · canonical/ubuntu linux
- Source
- psirt@cisco.com
References
- https://blog.clamav.net/2020/02/clamav-01022-security-patch-released.htmlRelease Notes, Vendor Advisory
- https://quickview.cloudapps.cisco.com/quickview/bug/CSCvs59062Third Party Advisory
- https://security.gentoo.org/glsa/202003-46Third Party Advisory
- https://usn.ubuntu.com/4280-1/Third Party Advisory
- https://usn.ubuntu.com/4280-2/Third Party Advisory
- https://blog.clamav.net/2020/02/clamav-01022-security-patch-released.htmlRelease Notes, Vendor Advisory
- https://quickview.cloudapps.cisco.com/quickview/bug/CSCvs59062Third Party Advisory
- https://security.gentoo.org/glsa/202003-46Third Party Advisory
- https://usn.ubuntu.com/4280-1/Third Party Advisory
- https://usn.ubuntu.com/4280-2/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.