PT-2025-26177 · Clamav+4 · Clamav+4

Volticks

·

Published

2025-01-01

·

Updated

2025-08-11

·

CVE-2025-20234

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ClamAV (affected versions not specified)
Description A vulnerability in Universal Disk Format (UDF) processing could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This issue is due to a memory overread during UDF file scanning. An attacker could exploit this by submitting a crafted file containing UDF content to be scanned by ClamAV. A successful exploit could allow the attacker to terminate the ClamAV scanning process, resulting in a DoS condition.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2025-08727
CVE-2025-20234
OPENSUSE-SU-2025:15211-1
SUSE-SU-2025:02119-1
SUSE-SU-2025:02200-1
SUSE-SU-2025:02201-1
SUSE-SU-2025_02119-1
SUSE-SU-2025_02200-1
SUSE-SU-2025_02201-1
USN-7615-1
USN-7615-2
ZDI-25-417

Affected Products

Clamav
Debian
Linuxmint
Suse
Ubuntu