CVE-2020-3481

CVSS 7.5 - HIGH
Description

A vulnerability in the EGG archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.0 - 0.102.3 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a null pointer dereference. An attacker could exploit this vulnerability by sending a crafted EGG file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process crash, resulting in a denial of service condition.

Affected Products
9
Vendor Product Version
clamav clamav All versions
canonical ubuntu_linux 12.04
canonical ubuntu_linux 14.04
canonical ubuntu_linux 16.04
canonical ubuntu_linux 18.04
canonical ubuntu_linux 20.04
debian debian_linux 9.0
fedoraproject fedora 31
fedoraproject fedora 32
Weakness Types
CWE-476 CWE-476
CVE Information
CVE ID:
CVE-2020-3481
Published:
2020-07-20
Modified:
2024-11-21
CVSS Score:
7.5
Severity:
HIGH
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Vendors
clamav debian fedoraproject canonical
Quick Actions
CVSS Severity Scale
0.0 - 3.9 LOW
4.0 - 6.9 MEDIUM
7.0 - 8.9 HIGH
9.0 - 10.0 CRITICAL