CVE-2024-20290: High severity Cisco Secure Endpoint Windows vulnerability
A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for end-of-string values during scanning, which may result in a heap buffer over-read. An attacker could exploit this vulnerability by submitting a crafted file containing OLE2 content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software and consuming available system resources. For a description of this vulnerability, see the ClamAV blog .
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/clamavto a version that resolves this vulnerability.Fixed in 1.0.5+dfsg-0ubuntu0.23.10.1 - Upgrade
Upgrade
ubuntu/clamavto a version that resolves this vulnerability.Fixed in 1.0.5+dfsg-1ubuntu1 - Upgrade
Upgrade
debian/clamavto a version that resolves this vulnerability.Fixed in 0.103.6+dfsg-0+deb10u1Fixed in 0.103.9+dfsg-0+deb10u1Fixed in 0.103.10+dfsg-0+deb11u1Fixed in 1.0.6+dfsg-1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-20290?
CVE-2024-20290 has a severity rating that indicates it could lead to a denial of service condition.
How do I fix CVE-2024-20290?
To fix CVE-2024-20290, upgrade ClamAV to the patched versions: 1.0.5+dfsg-0ubuntu0.23.10.1 or 1.0.5+dfsg-1ubuntu1 for Ubuntu, or the appropriate updates provided by Debian and Cisco.
Which systems are affected by CVE-2024-20290?
CVE-2024-20290 affects multiple versions of ClamAV across Ubuntu, Debian, and Cisco Secure Endpoint installations.
Can CVE-2024-20290 be exploited remotely?
Yes, CVE-2024-20290 can be exploited by an unauthenticated remote attacker.
What kind of vulnerability is CVE-2024-20290 categorized as?
CVE-2024-20290 is categorized as a denial of service vulnerability due to a flaw in the OLE2 file format parser in ClamAV.