USN-7229-1: ClamAV vulnerability
Published Jan 27, 2025
·Updated
It was discovered that ClamAV incorrectly handled decrypting OLE2 content. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service.
Affected Software
4 affected componentsFixes available
All of the following
ubuntu/clamav<1.4.2+dfsg-0ubuntu0.24.10.1
1.4.2+dfsg-0ubuntu0.24.10.1
Ubuntu Ubuntu=24.10
All of the following
ubuntu/clamav<1.0.8+dfsg-0ubuntu0.24.04.1
1.0.8+dfsg-0ubuntu0.24.04.1
Ubuntu Ubuntu=24.04
Event History
Jan 27, 2025
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7229-1?
The severity of USN-7229-1 is categorized as a denial of service vulnerability that can cause ClamAV to crash.
2
How do I fix USN-7229-1?
To fix USN-7229-1, update ClamAV to version 1.4.2+dfsg-0ubuntu0.24.10.1 for Ubuntu 24.10 or version 1.0.8+dfsg-0ubuntu0.24.04.1 for Ubuntu 24.04.
3
What causes the USN-7229-1 vulnerability?
USN-7229-1 is caused by ClamAV incorrectly handling the decryption of OLE2 content.
4
Who is affected by USN-7229-1?
USN-7229-1 affects users of ClamAV on Ubuntu versions 24.10 and 24.04.
5
Can USN-7229-1 be exploited remotely?
Yes, a remote attacker could exploit USN-7229-1 to potentially crash ClamAV, leading to a denial of service.