CVE-2019-12625: ClamAV Zip Bomb Vulnerability
Published Nov 5, 2019
·Updated
ClamAV versions prior to 0.101.3 are susceptible to a zip bomb vulnerability where an unauthenticated attacker can cause a denial of service condition by sending crafted messages to an affected system.
Affected Software
2 affected componentsFixes available
clamav clamav<0.101.3
debian/clamav
0.103.10+dfsg-0+deb11u11.0.7+dfsg-1~deb11u21.0.7+dfsg-1~deb12u11.4.2+dfsg-11.4.3+dfsg-1
Remediation
Event History
Nov 5, 2019
CVE Published
via MITRE·06:15 PM
Data Sourced
via MITRE·06:15 PM
DescriptionSeverityWeakness
Jan 11, 2024
Data Sourced
via Launchpad·11:16 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:11 AM
RemedyDescriptionSeverityAffected Software
Jul 5, 2025
Data Sourced
via Debian·04:19 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2019-12625?
CVE-2019-12625 is a zip bomb vulnerability in ClamAV versions prior to 0.101.3.
2
How does CVE-2019-12625 affect ClamAV?
CVE-2019-12625 allows an unauthenticated attacker to cause a denial of service by sending crafted messages to an affected system.
3
What is the severity of CVE-2019-12625?
CVE-2019-12625 has a severity rating of 7.5 (High).
4
How can I fix CVE-2019-12625?
To fix CVE-2019-12625, update ClamAV to version 0.101.3 or later.
5
Where can I find more information about CVE-2019-12625?
You can find more information about CVE-2019-12625 at the following references: [link1], [link2], [link3].