CVE-2020-3350
published 2020-06-18CVE-2020-3350: A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam AntiVirus could allow an authenticated, local attacker to cause the running…
PriorityP434medium6.3CVSS 3.1
AVLACHPRLUINSUCNIHAH
EPSS
0.26%
17.8th percentile
A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam AntiVirus could allow an authenticated, local attacker to cause the running software to delete arbitrary files on the system. The vulnerability is due to a race condition that could occur when scanning malicious files. An attacker with local shell access could exploit this vulnerability by executing a script that could trigger the race condition. A successful exploit could allow the attacker to delete arbitrary files on the system that the attacker would not normally have privileges to delete, producing system instability or causing the endpoint software to stop working.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| cisco | advanced_malware_protection_for_endpoints | < 1.12.4 | 1.12.4 |
| cisco | amp_for_endpoints_and_clamav | — | — |
| cisco | cisco_amp_for_endpoints | — | — |
| cisco | clam_antivirus | < 0.102.4 | 0.102.4 |
| clamav | clamav | >= 0 < 0.102.4+dfsg-1 | 0.102.4+dfsg-1 |
| clamav | clamav | >= 0 < 0.102.4+dfsg-1 | 0.102.4+dfsg-1 |
| clamav | clamav | >= 0 < 0.102.4+dfsg-1 | 0.102.4+dfsg-1 |
| clamav | clamav | >= 0 < 0.102.4+dfsg-1 | 0.102.4+dfsg-1 |
| clamav | clamav | >= 0 < 0.102.4+dfsg-0ubuntu0.16.04.1 | 0.102.4+dfsg-0ubuntu0.16.04.1 |
| clamav | clamav | >= 0 < 0.102.4+dfsg-0ubuntu0.18.04.1 | 0.102.4+dfsg-0ubuntu0.18.04.1 |
| clamav | clamav | >= 0 < 0.102.4+dfsg-0ubuntu0.20.04.1 | 0.102.4+dfsg-0ubuntu0.20.04.1 |
| clamav | clamav | >= 0 < 0.102.4+dfsg-0ubuntu0.14.04.1+esm1 | 0.102.4+dfsg-0ubuntu0.14.04.1+esm1 |
| debian | clamav | < clamav 0.102.4+dfsg-1 (bookworm) | clamav 0.102.4+dfsg-1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:N/I:P/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_cisco5.5MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
ClamAV vulnerabilities
vendor_ubuntu·2020-07-27·CVSS 7.5
CVE-2020-3481 [HIGH] ClamAV vulnerabilities
Title: ClamAV vulnerabilities
Summary: Several security issues were fixed in ClamAV.
It was discovered that ClamAV incorrectly handled parsing ARJ archives. A
remote attacker could possibly use this issue to cause ClamAV to crash,
resulting in a denial of service. (CVE-2020-3327)
It was discovered that ClamAV incorrectly handled scanning malicious files.
A local attacker could possibly use this issue to delete arbitrary files.
(CVE-2020-3350)
It was discovered that ClamAV incorrectly handled parsing EGG archives. A
remote attacker could possibly use this issue to cause ClamAV to crash,
resulting in a denial of service. (CVE-2020-3481)
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the neces
Ubuntu
ClamAV vulnerabilities
vendor_ubuntu·2020-07-27·CVSS 7.5
CVE-2020-3327 [HIGH] ClamAV vulnerabilities
Title: ClamAV vulnerabilities
Summary: Several security issues were fixed in ClamAV.
USN-4435-1 fixed several vulnerabilities in ClamAV. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that ClamAV incorrectly handled parsing ARJ archives. A
remote attacker could possibly use this issue to cause ClamAV to crash,
resulting in a denial of service. (CVE-2020-3327)
It was discovered that ClamAV incorrectly handled scanning malicious files.
A local attacker could possibly use this issue to delete arbitrary files.
(CVE-2020-3350)
It was discovered that ClamAV incorrectly handled parsing EGG archives. A
remote attacker could possibly use this issue to cause ClamAV to crash,
resulting in a denial of service.
Cisco
Cisco AMP for Endpoints and ClamAV Privilege Escalation Vulnerability
vendor_cisco·2020-06-17·CVSS 5.5
CVE-2020-3350 [MEDIUM] CWE-362 Cisco AMP for Endpoints and ClamAV Privilege Escalation Vulnerability
Cisco AMP for Endpoints and ClamAV Privilege Escalation Vulnerability
A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam AntiVirus could allow an authenticated, local attacker to cause the running software to delete arbitrary files on the system.
The vulnerability is due to a race condition that could occur when scanning malicious files. An attacker with local shell access could exploit this vulnerability by executing a script that could trigger the race condition. A successful exploit could allow the attacker to delete arbitrary files on the system that the attacker would not normally have privileges to delete, producing system instability or causing the endpoint software to stop working.
Cisco has released software updates that address this vulnerability. Ther
Debian
CVE-2020-3350: clamav - A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam Ant...
vendor_debian·2020·CVSS 5.5
CVE-2020-3350 [MEDIUM] CVE-2020-3350: clamav - A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam Ant...
A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam AntiVirus could allow an authenticated, local attacker to cause the running software to delete arbitrary files on the system. The vulnerability is due to a race condition that could occur when scanning malicious files. An attacker with local shell access could exploit this vulnerability by executing a script that could trigger the race condition. A successful exploit could allow the attacker to delete arbitrary files on the system that the attacker would not normally have privileges to delete, producing system instability or causing the endpoint software to stop working.
Scope: local
bookworm: resolved (fixed in 0.102.4+dfsg-1)
bullseye: resolved (fixed in 0.102.4+dfsg-1)
forky: resolved (fixed in 0.102.4+dfsg-1)
Cisco
Cisco AMP for Endpoints and ClamAV Privilege Escalation Vulnerability
vendor_cisco·CVSS 3.1
CVE-2020-3350 Cisco AMP for Endpoints and ClamAV Privilege Escalation Vulnerability
CVE-2020-3350: Cisco AMP for Endpoints and ClamAV Privilege Escalation Vulnerability
A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam AntiVirus could allow an authenticated, local attacker to cause the running software to delete arbitrary files on the system. The vulnerability is due to a race condition that could occur when scanning malicious files. An attacker with local shell access could exploit this vulnerability by executing a script that could trigger the race condition. A successful exploit could allow the attacker to delete arbitrary files on the system that the attacker would not normally have privileges to delete, producing system instability or causing the endpoint software to stop working. Cisco has released software updates that address this vulner
GHSA
GHSA-86pg-j5jw-f37r: A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam AntiVirus could allow an authenticated, local attacker to cause the runni
ghsa_unreviewed·2022-05-24
CVE-2020-3350 [LOW] CWE-362 GHSA-86pg-j5jw-f37r: A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam AntiVirus could allow an authenticated, local attacker to cause the runni
A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam AntiVirus could allow an authenticated, local attacker to cause the running software to delete arbitrary files on the system. The vulnerability is due to a race condition that could occur when scanning malicious files. An attacker with local shell access could exploit this vulnerability by executing a script that could trigger the race condition. A successful exploit could allow the attacker to delete arbitrary files on the system that the attacker would not normally have privileges to delete, producing system instability or causing the endpoint software to stop working.
OSV
clamav vulnerabilities
osv·2020-07-27·CVSS 7.5
CVE-2020-3327 [HIGH] clamav vulnerabilities
clamav vulnerabilities
USN-4435-1 fixed several vulnerabilities in ClamAV. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that ClamAV incorrectly handled parsing ARJ archives. A
remote attacker could possibly use this issue to cause ClamAV to crash,
resulting in a denial of service. (CVE-2020-3327)
It was discovered that ClamAV incorrectly handled scanning malicious files.
A local attacker could possibly use this issue to delete arbitrary files.
(CVE-2020-3350)
It was discovered that ClamAV incorrectly handled parsing EGG archives. A
remote attacker could possibly use this issue to cause ClamAV to crash,
resulting in a denial of service. (CVE-2020-3481)
OSV
clamav vulnerabilities
osv·2020-07-27·CVSS 7.5
CVE-2020-3327 [HIGH] clamav vulnerabilities
clamav vulnerabilities
It was discovered that ClamAV incorrectly handled parsing ARJ archives. A
remote attacker could possibly use this issue to cause ClamAV to crash,
resulting in a denial of service. (CVE-2020-3327)
It was discovered that ClamAV incorrectly handled scanning malicious files.
A local attacker could possibly use this issue to delete arbitrary files.
(CVE-2020-3350)
It was discovered that ClamAV incorrectly handled parsing EGG archives. A
remote attacker could possibly use this issue to cause ClamAV to crash,
resulting in a denial of service. (CVE-2020-3481)
OSV
CVE-2020-3350: A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam AntiVirus could allow an authenticated, local attacker to cause the runni
osv·2020-06-18·CVSS 6.3
CVE-2020-3350 [MEDIUM] CVE-2020-3350: A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam AntiVirus could allow an authenticated, local attacker to cause the runni
A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam AntiVirus could allow an authenticated, local attacker to cause the running software to delete arbitrary files on the system. The vulnerability is due to a race condition that could occur when scanning malicious files. An attacker with local shell access could exploit this vulnerability by executing a script that could trigger the race condition. A successful exploit could allow the attacker to delete arbitrary files on the system that the attacker would not normally have privileges to delete, producing system instability or causing the endpoint software to stop working.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-3350 clamav: malicious user exploit to replace scan target's directory with symlink
bugzilla·2020-07-17·CVSS 5.5
CVE-2020-3350 [MEDIUM] CVE-2020-3350 clamav: malicious user exploit to replace scan target's directory with symlink
CVE-2020-3350 clamav: malicious user exploit to replace scan target's directory with symlink
A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam AntiVirus could allow an authenticated, local attacker to cause the running software to delete arbitrary files on the system. The vulnerability is due to a race condition that could occur when scanning malicious files. An attacker with local shell access could exploit this vulnerability by executing a script that could trigger the race condition. A successful exploit could allow the attacker to delete arbitrary files on the system that the attacker would not normally have privileges to delete, producing system instability or causing the endpoint software to stop working.
References:
https://tools.cisco.com/security/cente
Bugzilla
CVE-2020-3350 clamav: malicious user exploit to replace scan target's directory with symlink [epel-all]
bugzilla·2020-07-17·CVSS 5.5
CVE-2020-3350 [MEDIUM] CVE-2020-3350 clamav: malicious user exploit to replace scan target's directory with symlink [epel-all]
CVE-2020-3350 clamav: malicious user exploit to replace scan target's directory with symlink [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mul
Bugzilla
CVE-2020-3350 clamav: malicious user exploit to replace scan target's directory with symlink [fedora-all]
bugzilla·2020-07-17·CVSS 5.5
CVE-2020-3350 [MEDIUM] CVE-2020-3350 clamav: malicious user exploit to replace scan target's directory with symlink [fedora-all]
CVE-2020-3350 clamav: malicious user exploit to replace scan target's directory with symlink [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2020-4044 xrdp: buffer overflow via malicious payloads
bugzilla·2020-07-09·CVSS 7.5
CVE-2020-4044 [HIGH] CVE-2020-4044 xrdp: buffer overflow via malicious payloads
CVE-2020-4044 xrdp: buffer overflow via malicious payloads
The xrdp-sesman service before version 0.9.13.1 can be crashed by connecting over port 3350 and supplying a malicious payload. Once the xrdp-sesman process is dead, an unprivileged attacker on the server could then proceed to start their own imposter sesman service listening on port 3350. This will allow them to capture any user credentials that are submitted to XRDP and approve or reject arbitrary login credentials. For xorgxrdp sessions in particular, this allows an unauthorized user to hijack an existing session. This is a buffer overflow attack, so there may be a risk of arbitrary code execution as well.
References:
https://github.com/neutrinolabs/xrdp/commit/0c791d073d0eb344ee7aaafd221513dc9226762c
https://github.com/neutrin
https://lists.debian.org/debian-lts-announce/2020/08/msg00010.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IJ67VH37NCG25PICGWFWZHSVG7PBT7MC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QM7EXJHDEZJLWM2NKH6TCDXOBP5NNYIN/https://security.gentoo.org/glsa/202007-23https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-famp-ZEpdXyhttps://usn.ubuntu.com/4435-1/https://usn.ubuntu.com/4435-2/https://lists.debian.org/debian-lts-announce/2020/08/msg00010.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IJ67VH37NCG25PICGWFWZHSVG7PBT7MC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QM7EXJHDEZJLWM2NKH6TCDXOBP5NNYIN/https://security.gentoo.org/glsa/202007-23https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-famp-ZEpdXyhttps://usn.ubuntu.com/4435-1/https://usn.ubuntu.com/4435-2/
2020-06-18
Published