USN-4435-1: ClamAV vulnerabilities
It was discovered that ClamAV incorrectly handled parsing ARJ archives. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2020-3327) It was discovered that ClamAV incorrectly handled scanning malicious files. A local attacker could possibly use this issue to delete arbitrary files. (CVE-2020-3350) It was discovered that ClamAV incorrectly handled parsing EGG archives. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2020-3481)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this advisory?
The vulnerability ID for this advisory is USN-4435-1.
What is the severity of USN-4435-1?
The severity of USN-4435-1 is not mentioned in the advisory. Please refer to the provided references for more information.
What is the affected software for USN-4435-1?
The affected software for USN-4435-1 is ClamAV.
How can a remote attacker exploit the vulnerability in USN-4435-1?
A remote attacker could exploit the vulnerability by using specially crafted ARJ archives, causing ClamAV to crash and resulting in a denial of service.
How can a local attacker exploit the vulnerability in USN-4435-1?
A local attacker could exploit the vulnerability by scanning malicious files, leading to a possible privilege escalation.
How can I fix USN-4435-1?
To fix USN-4435-1, update ClamAV to version 0.102.4+dfsg-0ubuntu0.20.04.1 for Ubuntu 20.04, version 0.102.4+dfsg-0ubuntu0.18.04.1 for Ubuntu 18.04, or version 0.102.4+dfsg-0ubuntu0.16.04.1 for Ubuntu 16.04.