cisco-sa-clamav-q8DThCy: ClamAV HFS+ Partition Scanning Buffer Overflow Vulnerability Affecting Cisco Products: February 2023
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed:A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-clamav-q8DThCy?
The severity of cisco-sa-clamav-q8DThCy is classified as high due to the potential for remote code execution by unauthenticated attackers.
How do I fix cisco-sa-clamav-q8DThCy?
To fix cisco-sa-clamav-q8DThCy, upgrade ClamAV to version 1.0.1 or higher, 0.105.2 or higher, or 0.103.8 or higher.
What software versions are affected by cisco-sa-clamav-q8DThCy?
The affected software versions are ClamAV 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier.
What type of attacker can exploit cisco-sa-clamav-q8DThCy?
cisco-sa-clamav-q8DThCy can be exploited by an unauthenticated remote attacker.
What is the impact of the vulnerability in cisco-sa-clamav-q8DThCy?
The impact of the vulnerability in cisco-sa-clamav-q8DThCy may allow remote arbitrary code execution on the affected systems.