USN-7011-1: ClamAV vulnerabilities
It was discovered that ClamAV incorrectly handled certain PDF files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2024-20505) It was discovered that ClamAV incorrectly handled logfile privileges. A local attacker could use this issue to cause ClamAV to overwrite arbitrary files, possibly leading to privilege escalation. (CVE-2024-20506)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7011-1?
USN-7011-1 has a severity rating that may allow an attacker to cause a denial of service through specific vulnerabilities in ClamAV.
How do I fix USN-7011-1?
To fix USN-7011-1, upgrade ClamAV to the recommended patched versions for your operating system releases.
What vulnerabilities are addressed in USN-7011-1?
USN-7011-1 addresses vulnerabilities related to improper handling of PDF files and logfile privileges in ClamAV.
Who is affected by USN-7011-1?
Users of specific versions of ClamAV on Ubuntu 20.04, 22.04, and 24.04 are affected by USN-7011-1.
What is the impact of the vulnerabilities in USN-7011-1?
The impact of the vulnerabilities in USN-7011-1 may lead to crashes or denial of service for users running vulnerable ClamAV versions.