QID 198636

Date Published: 2022-01-19

QID 198636: Ubuntu Security Notification for ClamAV Vulnerability (USN-5233-1)

Clamav incorrectly handled memory when thecl_scan_general_collect_metadata scan option was enabled.

A remote attackercould possibly use this issue to cause clamav to crash, resulting in adenial of service.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5233-1 for updates and patch information.
    Vendor References

    CVEs related to QID 198636

    Software Advisories
    Advisory ID Software Component Link
    USN-5233-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5233-1