PT-2026-7942 · Cisco · Clamav

CVE-2020-37167

·

Publicado

2020-07-22

·

Atualizado

2026-02-27

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ClamAV versions prior to 0.102.0
Description The ClamAV ClamBC bytecode interpreter has a flaw in how it handles function names. This allows manipulation of bytecode function names due to weak input validation in function name encoding. Successful exploitation could lead to the execution of malicious bytecode or cause unpredictable behavior within the ClamAV engine.
Recommendations Update ClamAV to a version newer than 0.102.0.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-02545
CVE-2020-37167

Produtos afetados

Clamav