https://seclists.org/oss-sec/2025/q2/269: ClamAV 1.4.3 and 1.0.9 security patch versions published
Published Jun 20, 2025
·Updated
Affected Software
1 affected component
clamav clamav
Frequently Asked Questions
1
What is the severity of CVE-2025-20260?
CVE-2025-20260 has been classified as a high severity vulnerability due to its potential to cause a denial-of-service condition.
2
How do I fix CVE-2025-20260?
To fix CVE-2025-20260, update to the ClamAV versions 1.4.3 or 1.0.9, which include the security patch.
3
What is CVE-2025-20260 related to?
CVE-2025-20260 is related to a buffer overflow write bug in the PDF file parser of ClamAV.
4
Can CVE-2025-20260 lead to unauthorized access?
CVE-2025-20260 primarily leads to a denial-of-service condition and does not inherently allow for unauthorized access.
5
Are older versions of ClamAV affected by CVE-2025-20260?
Yes, older versions of ClamAV prior to 1.4.3 and 1.0.9 are affected by CVE-2025-20260 and should be updated.