PT-2026-7942 · Cisco · Clamav

Published

2020-07-22

·

Updated

2026-02-27

·

CVE-2020-37167

CVSS v3.1
10
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ClamAV versions prior to 0.102.0
Description The ClamAV ClamBC bytecode interpreter has a flaw in how it handles function names. This allows manipulation of bytecode function names due to weak input validation in function name encoding. Successful exploitation could lead to the execution of malicious bytecode or cause unpredictable behavior within the ClamAV engine.
Recommendations Update ClamAV to a version newer than 0.102.0.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2026-02545
CVE-2020-37167

Affected Products

Clamav