cisco-sa-clamav-dos-vL9x58p4: ClamAV Truncated File Denial of Service Vulnerability Affecting Cisco Products: May 2022
On May 4, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in Clam AntiVirus (ClamAV) versions 0.103.4, 0.103.5, 0.104.1, and 0.104.2 could allow an authenticated, local attacker to cause a denial of service condition on an affected device. For a description of this vulnerability, see the ClamAV blog. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-dos-vL9x58p4
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-clamav-dos-vL9x58p4?
The severity of cisco-sa-clamav-dos-vL9x58p4 is rated as high due to the potential for denial of service attacks.
How do I fix cisco-sa-clamav-dos-vL9x58p4?
To fix cisco-sa-clamav-dos-vL9x58p4, upgrade ClamAV to versions 0.103.6 or later, or 0.104.3 or later.
Who is affected by cisco-sa-clamav-dos-vL9x58p4?
cisco-sa-clamav-dos-vL9x58p4 affects users of ClamAV versions 0.103.4, 0.103.5, 0.104.1, and 0.104.2.
What type of attack does cisco-sa-clamav-dos-vL9x58p4 enable?
cisco-sa-clamav-dos-vL9x58p4 enables authenticated local attackers to execute denial of service attacks.
When was the vulnerability cisco-sa-clamav-dos-vL9x58p4 disclosed?
The vulnerability cisco-sa-clamav-dos-vL9x58p4 was disclosed on May 4, 2022.