CVE-2020-3327

CVSS 7.5 - HIGH
Description

A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a heap buffer overflow read. An attacker could exploit this vulnerability by sending a crafted ARJ file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process crash, resulting in a denial of service condition.

Affected Products
12
Vendor Product Version
cisco clam_antivirus All versions
debian debian_linux 8.0
debian debian_linux 9.0
fedoraproject fedora 30
fedoraproject fedora 31
fedoraproject fedora 32
canonical ubuntu_linux 12.04
canonical ubuntu_linux 14.04
canonical ubuntu_linux 16.04
canonical ubuntu_linux 18.04
canonical ubuntu_linux 19.10
canonical ubuntu_linux 20.04
Weakness Types
CWE-20 CWE-20
CVE Information
CVE ID:
CVE-2020-3327
Published:
2020-05-13
Modified:
2024-11-21
CVSS Score:
7.5
Severity:
HIGH
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Vendors
fedoraproject cisco debian canonical
Quick Actions
CVSS Severity Scale
0.0 - 3.9 LOW
4.0 - 6.9 MEDIUM
7.0 - 8.9 HIGH
9.0 - 10.0 CRITICAL