First published: Tue Nov 05 2019(Updated: )
ClamAV versions prior to 0.101.3 are susceptible to a zip bomb vulnerability where an unauthenticated attacker can cause a denial of service condition by sending crafted messages to an affected system.
Credit: ykramarz@cisco.com psirt@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/clamav | 0.103.10+dfsg-0+deb11u1 1.0.7+dfsg-1~deb11u2 1.0.7+dfsg-1~deb12u1 1.4.2+dfsg-1 | |
ClamAV | <0.101.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12625 is a zip bomb vulnerability in ClamAV versions prior to 0.101.3.
CVE-2019-12625 allows an unauthenticated attacker to cause a denial of service by sending crafted messages to an affected system.
CVE-2019-12625 has a severity rating of 7.5 (High).
To fix CVE-2019-12625, update ClamAV to version 0.101.3 or later.
You can find more information about CVE-2019-12625 at the following references: [link1], [link2], [link3].