PT-2022-2863 · Clamav+5 · Clamav+5

Michał Dardas

·

Published

2022-05-04

·

Updated

2024-06-15

·

CVE-2022-20792

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ClamAV versions 0.104.0 through 0.104.2 ClamAV LTS version 0.103.5 and prior versions
Description The issue is related to a heap buffer overflow due to improper bounds checking in the regex module used by the signature database load module. This could allow an authenticated, local attacker to crash ClamAV at database load time and possibly gain code execution. An attacker could exploit this by placing a crafted CDB ClamAV signature database file in the ClamAV database directory, potentially allowing them to run code as the clamav user.
Recommendations For ClamAV versions 0.104.0 through 0.104.2, consider updating to a version that includes the fix for this issue. For ClamAV LTS version 0.103.5 and prior versions, update to a newer version that includes the fix. As a temporary workaround, consider restricting access to the ClamAV database directory to prevent attackers from placing crafted signature database files. Avoid using the vulnerable regex module until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Memory Corruption

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1906
ALT-PU-2022-1924
ALT-PU-2022-1939
ALT-PU-2022-1945
BDU:2022-03420
CVE-2022-20792
DLA-3042-1
MGASA-2022-0187
OESA-2022-1683
OPENSUSE-SU-2022_1644-1
OPENSUSE-SU-2024:12047-1
SUSE-SU-2022:1644-1
SUSE-SU-2022:1647-1
SUSE-SU-2022_1644-1
SUSE-SU-2022_1647-1
USN-5423-1
USN-5423-2

Affected Products

Alt Linux
Clamav
Linuxmint
Red Os
Suse
Ubuntu