CVE-2020-3123

Name
CVE-2020-3123
Description
A vulnerability in the Data-Loss-Prevention (DLP) module in Clam AntiVirus (ClamAV) Software versions 0.102.1 and 0.102.0 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to an out-of-bounds read affecting users that have enabled the optional DLP feature. An attacker could exploit this vulnerability by sending a crafted email file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process crash, resulting in a denial of service condition.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Third Party Advisory https://quickview.cloudapps.cisco.com/quickview/bug/CSCvs59062
CONFIRM https://blog.clamav.net/2020/02/clamav-01022-security-patch-released.html
UBUNTU https://usn.ubuntu.com/4280-1/
UBUNTU https://usn.ubuntu.com/4280-2/
GENTOO https://security.gentoo.org/glsa/202003-46

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:clamav:clamav:0.102.0:*:*:*:*:*:*:* clamav == None == 0.102.0
cpe:2.3:a:clamav:clamav:0.102.1:*:*:*:*:*:*:* clamav == None == 0.102.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status