PT-2026-7942 · Cisco · Clamav

CVE-2020-37167

·

Published

2020-07-22

·

Updated

2026-02-27

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ClamAV versions prior to 0.102.0
Description The ClamAV ClamBC bytecode interpreter has a flaw in how it handles function names. This allows manipulation of bytecode function names due to weak input validation in function name encoding. Successful exploitation could lead to the execution of malicious bytecode or cause unpredictable behavior within the ClamAV engine.
Recommendations Update ClamAV to a version newer than 0.102.0.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02545
CVE-2020-37167

Affected Products

Clamav