NULL Pointer Dereference Affecting clamav package, versions [0.102.0,0.102.4)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
1.97% (89th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about NULL Pointer Dereference vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-UNMANAGED-CLAMAV-2381114
  • published26 Jan 2022
  • disclosed20 Jul 2020
  • creditUnknown

Introduced: 20 Jul 2020

CVE-2020-3481  (opens in a new tab)
CWE-476  (opens in a new tab)

How to fix?

Upgrade clamav to version 0.102.4 or higher.

Overview

Affected versions of this package are vulnerable to NULL Pointer Dereference. A vulnerability in the EGG archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.0 - 0.102.3 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a null pointer dereference. An attacker could exploit this vulnerability by sending a crafted EGG file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process crash, resulting in a denial of service condition.

References

CVSS Scores

version 3.1