PT-2025-1255 · Clamav+4 · Clamav+4
Published
2025-01-22
·
Updated
2026-02-10
·
CVE-2025-20128
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
ClamAV versions 1.0.0 through 1.4.1
Description:
A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an integer underflow in a bounds check that allows for a heap buffer overflow read. An attacker could exploit this vulnerability by submitting a crafted file containing OLE2 content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process, resulting in a DoS condition on the affected software. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Recommendations:
ClamAV versions 1.0.0 through 1.4.1 should be updated to version 1.4.2 or later to address the vulnerability.
ClamAV version 1.0.8 or earlier should be updated to version 1.0.8 or later, however, it is recommended to update to the latest version available.
Fix
DoS
Heap Based Buffer Overflow
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Clamav
Debian
Linuxmint
Suse
Ubuntu