PT-2022-1458 · Unknown+5 · Clam Antivirus+5

Laurent Delosieres

·

Published

2022-01-13

·

Updated

2026-02-06

·

CVE-2022-20698

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Clam AntiVirus versions 0.103.4 and prior versions Clam AntiVirus version 0.104.1
Description The issue is related to insufficient input validation in the OOXML parsing module. An attacker could exploit this by sending a specially crafted OOXML file to an affected device, potentially causing a denial of service condition due to improper checks that may result in an invalid pointer read. This could allow the attacker to crash the ClamAV scanning process.
Recommendations For Clam AntiVirus versions 0.103.4 and prior versions, update to a version that includes the fix for this issue. For Clam AntiVirus version 0.104.1, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting the processing of OOXML files until a patch is available.

Exploit

Fix

DoS

Out of bounds Read

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1071
ALT-PU-2022-1113
ALT-PU-2022-1129
ALT-PU-2022-1152
AZL-7532
BDU:2022-00587
CLEANSTART-2026-LA13761
CLEANSTART-2026-NJ87139
CLEANSTART-2026-TC95380
CLEANSTART-2026-WX01708
CVE-2022-20698
MGASA-2022-0024
OESA-2022-1508
OPENSUSE-SU-2022:0493-1
OPENSUSE-SU-2022_0493-1
OPENSUSE-SU-2024:11748-1
ROSA-SA-2023-2285
SUSE-SU-2022:0160-1
SUSE-SU-2022:0358-1
SUSE-SU-2022:0493-1
SUSE-SU-2022:14882-1
SUSE-SU-2022_0160-1
SUSE-SU-2022_0358-1
SUSE-SU-2022_0493-1
SUSE-SU-2022_14882-1
USN-5233-1
USN-5233-2

Affected Products

Alt Linux
Clam Antivirus
Linuxmint
Red Os
Suse
Ubuntu