USN-4370-1: ClamAV vulnerabilities
It was discovered that ClamAV incorrectly handled parsing ARJ archives. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2020-3327) It was discovered that ClamAV incorrectly handled parsing PDF files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2020-3341)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this advisory?
The vulnerability ID for this advisory is USN-4370-1.
What software is affected by this vulnerability?
ClamAV is affected by this vulnerability.
What is the severity of the ClamAV vulnerability (CVE-2020-3327)?
The severity of the ClamAV vulnerability (CVE-2020-3327) is not specified in the advisory.
How can I fix the ClamAV vulnerability (CVE-2020-3327)?
To fix the ClamAV vulnerability (CVE-2020-3327), update ClamAV to version 0.102.3+dfsg-0ubuntu0.20.04.1 or later.
Where can I find more information about this ClamAV vulnerability?
You can find more information about this ClamAV vulnerability in the Ubuntu Security Notices USN-4370-1 advisory.