ClamAV
cpe:2.3:a:clamav:clamav:*:*:*:*:*:*:*
- >= 1.0.0
A denial-of-service vulnerability has been identified in ClamAV's Object Linking and Embedding 2 (OLE2) decryption routine. This issue allows an unauthenticated, remote attacker to cause a DoS condition on affected devices. The vulnerability arises from an integer underflow in a bounds check, leading to a heap buffer overflow read. Exploitation involves submitting a crafted file with OLE2 content for ClamAV to scan. A successful exploit can crash the ClamAV scanning process, disrupting ongoing operations.
Exploitation of this vulnerability causes the ClamAV scanning process to crash, interrupting or delaying file scanning operations. However, it does not affect the overall stability of the system.
Users can upgrade to ClamAV versions 1.4.2 or 1.0.8, both of which include the necessary fix. These versions are available on the ClamAV downloads page, the GitHub Release page, and through Docker Hub. For Cisco Secure Endpoint users, updated connectors are available through the Cisco Secure Endpoint portal or the connector repository for Cisco Secure Endpoint Private Cloud.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.