CVE-2023-20197
Summary
| CVE | CVE-2023-20197 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-16 22:15:00 UTC |
| Updated | 2024-01-25 17:15:00 UTC |
| Description | A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to an incorrect check for completion when a file is decompressed, which may result in a loop condition that could cause the affected software to stop responding. An attacker could exploit this vulnerability by submitting a crafted HFS+ filesystem image to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to stop responding, resulting in a DoS condition on the affected software and consuming available system resources.
For a description of this vulnerability, see the ClamAV blog . |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 38 Update: clamav-1.0.2-1.fc38 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| [SECURITY] [DLA 3544-1] clamav security update |
MISC |
lists.debian.org |
|
| [SECURITY] Fedora 37 Update: clamav-0.103.9-1.fc37 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| ClamAV HFS+ File Scanning Infinite Loop Denial of Service Vulnerability |
MISC |
sec.cloudapps.cisco.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 199673 Ubuntu Security Notification for ClamAV Vulnerability (USN-6303-1)
- 199674 Ubuntu Security Notification for ClamAV Vulnerability (USN-6303-2)
- 284432 Fedora Security Update for clamav (FEDORA-2023-bf72d8833e)
- 505992 Alpine Linux Security Update for clamav
- 6000083 Debian Security Update for clamav (DLA 3544-1)
- 691235 Free Berkeley Software Distribution (FreeBSD) Security Update for clamav (51a59f36-3c58-11ee-b32e-080027f5fec9)