First published: Tue Feb 18 2020(Updated: )
USN-4280-1 fixed a vulnerability in ClamAV. This update provides the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM. Original advisory details: It was discovered that ClamAV incorrectly handled memory when the Data-Loss-Prevention (DLP) feature was enabled. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/clamav | <0.102.2+dfsg-0ubuntu0.14.04.1+esm1 | 0.102.2+dfsg-0ubuntu0.14.04.1+esm1 |
Ubuntu Ubuntu | =14.04 | |
All of | ||
ubuntu/clamav | <0.102.2+dfsg-0ubuntu0.12.04.1 | 0.102.2+dfsg-0ubuntu0.12.04.1 |
Ubuntu Ubuntu | =12.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this ClamAV vulnerability is USN-4280-2.
The affected software for this vulnerability is ClamAV on Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
The severity level of this vulnerability is not provided in the given information.
To fix this vulnerability, update ClamAV to version 0.102.2+dfsg-0ubuntu0.14.04.1+esm1 for Ubuntu 14.04 ESM and version 0.102.2+dfsg-0ubuntu0.12.04.1 for Ubuntu 12.04 ESM.
You can find more information about this vulnerability at the following references: [CVE-2020-3123](https://ubuntu.com/security/CVE-2020-3123), [USN-4280-1](https://ubuntu.com/security/notices/USN-4280-1), [ClamAV Launchpad](https://launchpad.net/ubuntu/+source/clamav/0.102.2+dfsg-0ubuntu0.14.04.1+esm1)