USN-6303-1: ClamAV vulnerability
Published Aug 21, 2023
·Updated
It was discovered that ClamAV incorrectly handled parsing HFS+ files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service.
Affected Software
6 affected componentsFixes available
All of the following
ubuntu/clamav<0.103.9+dfsg-0ubuntu0.23.04.1
0.103.9+dfsg-0ubuntu0.23.04.1
Ubuntu Ubuntu=23.04
All of the following
ubuntu/clamav<0.103.9+dfsg-0ubuntu0.22.04.1
0.103.9+dfsg-0ubuntu0.22.04.1
Ubuntu Ubuntu=22.04
All of the following
ubuntu/clamav<0.103.9+dfsg-0ubuntu0.20.04.1
0.103.9+dfsg-0ubuntu0.20.04.1
Ubuntu Ubuntu=20.04
Event History
Aug 21, 2023
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID for this ClamAV vulnerability?
The vulnerability ID for this ClamAV vulnerability is USN-6303-1.
2
What is the severity of the ClamAV vulnerability?
The severity of the ClamAV vulnerability is not mentioned in the provided information.
3
How can a remote attacker exploit this ClamAV vulnerability?
A remote attacker could exploit this ClamAV vulnerability by using it to cause ClamAV to crash, resulting in a denial of service.
4
Which versions of Ubuntu are affected by this ClamAV vulnerability?
Versions 23.04, 22.04, and 20.04 of Ubuntu are affected by this ClamAV vulnerability.
5
How can I fix this ClamAV vulnerability?
To fix this ClamAV vulnerability, update ClamAV to version 0.103.9+dfsg-0ubuntu0.23.04.1, 0.103.9+dfsg-0ubuntu0.22.04.1, or 0.103.9+dfsg-0ubuntu0.20.04.1 depending on your Ubuntu version.