CVE-2020-4435
published 2020-06-10CVE-2020-4435: Certain IBM Aspera applications are vulnerable to arbitrary memory corruption based on the product configuration, which could allow an attacker with intimate…
PriorityP344high7.5CVSS 3.1
AVNACHPRLUINSUCHIHAH
EPSS
1.62%
73.2th percentile
Certain IBM Aspera applications are vulnerable to arbitrary memory corruption based on the product configuration, which could allow an attacker with intimate knowledge of the system to execute arbitrary code or perform a denial-of-service (DoS) through the http fallback service. IBM X-Force ID: 180901.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| clamav | clamav | >= 0 < 0.102.4+dfsg-0ubuntu0.14.04.1+esm1 | 0.102.4+dfsg-0ubuntu0.14.04.1+esm1 |
| ibm | aspera_application_platform_on_demand | <= 3.7.4 | — |
| ibm | aspera_application_platform_on_demand | — | — |
| ibm | aspera_faspex_on_demand | <= 3.7.4 | — |
| ibm | aspera_faspex_on_demand | — | — |
| ibm | aspera_high-speed_transfer_endpoint | <= 3.9.3 | — |
| ibm | aspera_high-speed_transfer_endpoint | — | — |
| ibm | aspera_high-speed_transfer_server | <= 3.9.3 | — |
| ibm | aspera_high-speed_transfer_server | — | — |
| ibm | aspera_high-speed_transfer_server_for_cloud_pak_for_integration | <= 3.9.10 | — |
| ibm | aspera_high-speed_transfer_server_for_cloud_pak_for_integration | — | — |
| ibm | aspera_proxy_server | <= 1.4.3 | — |
| ibm | aspera_proxy_server | — | — |
| ibm | aspera_server_on_demand | <= 3.7.4 | — |
| ibm | aspera_server_on_demand | — | — |
| ibm | aspera_shares_on_demand | <= 3.7.4 | — |
| ibm | aspera_shares_on_demand | — | — |
| ibm | aspera_streaming | <= 3.9.3 | — |
| ibm | aspera_streaming | — | — |
| ibm | aspera_transfer_cluster_manager | <= 1.3.1 | — |
| ibm | aspera_transfer_cluster_manager | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m3fx-xfxm-w2qv: Certain IBM Aspera applications are vulnerable to arbitrary memory corruption based on the product configuration, which could allow an attacker with i
ghsa_unreviewed·2022-05-24
CVE-2020-4435 [MEDIUM] CWE-119 GHSA-m3fx-xfxm-w2qv: Certain IBM Aspera applications are vulnerable to arbitrary memory corruption based on the product configuration, which could allow an attacker with i
Certain IBM Aspera applications are vulnerable to arbitrary memory corruption based on the product configuration, which could allow an attacker with intimate knowledge of the system to execute arbitrary code or perform a denial-of-service (DoS) through the http fallback service. IBM X-Force ID: 180901.
OSV
clamav vulnerabilities
osv·2020-07-27·CVSS 7.5
CVE-2020-3327 clamav vulnerabilities
clamav vulnerabilities
USN-4435-1 fixed several vulnerabilities in ClamAV. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that ClamAV incorrectly handled parsing ARJ archives. A
remote attacker could possibly use this issue to cause ClamAV to crash,
resulting in a denial of service. (CVE-2020-3327)
It was discovered that ClamAV incorrectly handled scanning malicious files.
A local attacker could possibly use this issue to delete arbitrary files.
(CVE-2020-3350)
It was discovered that ClamAV incorrectly handled parsing EGG archives. A
remote attacker could possibly use this issue to cause ClamAV to crash,
resulting in a denial of service. (CVE-2020-3481)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-06-10
Published