CVE-2020-3350
Summary
| CVE | CVE-2020-3350 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-18 03:15:00 UTC |
| Updated | 2023-11-07 03:22:00 UTC |
| Description | A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam AntiVirus could allow an authenticated, local attacker to cause the running software to delete arbitrary files on the system. The vulnerability is due to a race condition that could occur when scanning malicious files. An attacker with local shell access could exploit this vulnerability by executing a script that could trigger the race condition. A successful exploit could allow the attacker to delete arbitrary files on the system that the attacker would not normally have privileges to delete, producing system instability or causing the endpoint software to stop working. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 31 Update: clamav-0.102.4-1.fc31 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 32 Update: clamav-0.102.4-1.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| USN-4435-2: ClamAV vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
|
| Cisco AMP for Endpoints and ClamAV Privilege Escalation Vulnerability |
CISCO |
tools.cisco.com |
Vendor Advisory |
| USN-4435-1: ClamAV vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
|
| [SECURITY] Fedora 31 Update: clamav-0.102.4-1.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| ClamAV: Multiple vulnerabilities (GLSA 202007-23) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [SECURITY] Fedora 32 Update: clamav-0.102.4-1.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] [DLA 2314-1] clamav security update |
MLIST |
lists.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500099 Alpine Linux Security Update for clamav
- 503824 Alpine Linux Security Update for clamav
- 690450 Free Berkeley Software Distribution (FreeBSD) Security Update for clamav (f7a02651-c798-11ea-81d6-6805cabe6ebb)
- 750483 OpenSUSE Security Update for clamav (openSUSE-SU-2020:2276-1)
- 750485 OpenSUSE Security Update for clamav (openSUSE-SU-2020:2268-1)