CVE-2022-20792
published 2022-08-10CVE-2022-20792: A vulnerability in the regex module used by the signature database load module of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version…
PriorityP338high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.51%
40.4th percentile
A vulnerability in the regex module used by the signature database load module of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior versions could allow an authenticated, local attacker to crash ClamAV at database load time, and possibly gain code execution. The vulnerability is due to improper bounds checking that may result in a multi-byte heap buffer overwflow write. An attacker could exploit this vulnerability by placing a crafted CDB ClamAV signature database file in the ClamAV database directory. An exploit could allow the attacker to run code as the clamav user.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | clam_antivirus | >= 0.104.0 < unspecified | unspecified |
| cisco | clam_antivirus | unspecified – 0.104.2 | — |
| cisco | telepresence_collaboration_endpoint_and_roomos | — | — |
| clamav | clamav | <= 0.103.5 | — |
| clamav | clamav | >= 0 < 0.103.6+dfsg-0+deb11u1 | 0.103.6+dfsg-0+deb11u1 |
| clamav | clamav | >= 0 < 0.103.6+dfsg-1 | 0.103.6+dfsg-1 |
| clamav | clamav | >= 0 < 0.103.6+dfsg-1 | 0.103.6+dfsg-1 |
| clamav | clamav | >= 0 < 0.103.6+dfsg-1 | 0.103.6+dfsg-1 |
| clamav | clamav | >= 0 < 0.103.6+dfsg-0ubuntu0.18.04.1 | 0.103.6+dfsg-0ubuntu0.18.04.1 |
| clamav | clamav | >= 0 < 0.103.6+dfsg-0ubuntu0.20.04.1 | 0.103.6+dfsg-0ubuntu0.20.04.1 |
| clamav | clamav | >= 0 < 0.103.6+dfsg-0ubuntu0.22.04.1 | 0.103.6+dfsg-0ubuntu0.22.04.1 |
| clamav | clamav | >= 0 < 0.103.6+dfsg-0ubuntu0.14.04.1+esm1 | 0.103.6+dfsg-0ubuntu0.14.04.1+esm1 |
| clamav | clamav | >= 0 < 0.103.6+dfsg-0ubuntu0.16.04.1+esm1 | 0.103.6+dfsg-0ubuntu0.16.04.1+esm1 |
| clamav | clamav | 0.104.0 – 0.104.2 | — |
| debian | clamav | < clamav 0.103.6+dfsg-1 (bookworm) | clamav 0.103.6+dfsg-1 (bookworm) |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_ubuntu8.6HIGH
vendor_debian7.8HIGH
vendor_cisco3.1
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c59m-xfxc-m38p: A vulnerability in the regex module used by the signature database load module of Clam AntiVirus (ClamAV) versions 0
ghsa_unreviewed·2022-08-11
CVE-2022-20792 [HIGH] CWE-125 GHSA-c59m-xfxc-m38p: A vulnerability in the regex module used by the signature database load module of Clam AntiVirus (ClamAV) versions 0
A vulnerability in the regex module used by the signature database load module of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior versions could allow an authenticated, local attacker to crash ClamAV at database load time, and possibly gain code execution. The vulnerability is due to improper bounds checking that may result in a multi-byte heap buffer overwflow write. An attacker could exploit this vulnerability by placing a crafted CDB ClamAV signature database file in the ClamAV database directory. An exploit could allow the attacker to run code as the clamav user.
OSV
CVE-2022-20792: A vulnerability in the regex module used by the signature database load module of Clam AntiVirus (ClamAV) versions 0
osv·2022-08-10·CVSS 7.8
CVE-2022-20792 [HIGH] CVE-2022-20792: A vulnerability in the regex module used by the signature database load module of Clam AntiVirus (ClamAV) versions 0
A vulnerability in the regex module used by the signature database load module of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior versions could allow an authenticated, local attacker to crash ClamAV at database load time, and possibly gain code execution. The vulnerability is due to improper bounds checking that may result in a multi-byte heap buffer overwflow write. An attacker could exploit this vulnerability by placing a crafted CDB ClamAV signature database file in the ClamAV database directory. An exploit could allow the attacker to run code as the clamav user.
OSV
clamav vulnerabilities
osv·2022-05-17·CVSS 7.5
CVE-2022-20770 [HIGH] clamav vulnerabilities
clamav vulnerabilities
USN-5423-1 fixed several vulnerabilities in ClamAV. This update provides
the corresponding update for Ubuntu 14.04 ESM and 16.04 ESM.
Original advisory details:
Michał Dardas discovered that ClamAV incorrectly handled parsing CHM files.
A remote attacker could possibly use this issue to cause ClamAV to stop
responding, resulting in a denial of service. (CVE-2022-20770)
Michał Dardas discovered that ClamAV incorrectly handled parsing TIFF
files. A remote attacker could possibly use this issue to cause ClamAV to
stop responding, resulting in a denial of service. (CVE-2022-20771)
Michał Dardas discovered that ClamAV incorrectly handled parsing HTML
files. A remote attacker could possibly use this issue to cause ClamAV to
consume resources, resulting in a denial of
OSV
clamav vulnerabilities
osv·2022-05-17·CVSS 7.5
CVE-2022-20770 [HIGH] clamav vulnerabilities
clamav vulnerabilities
Michał Dardas discovered that ClamAV incorrectly handled parsing CHM files.
A remote attacker could possibly use this issue to cause ClamAV to stop
responding, resulting in a denial of service. (CVE-2022-20770)
Michał Dardas discovered that ClamAV incorrectly handled parsing TIFF
files. A remote attacker could possibly use this issue to cause ClamAV to
stop responding, resulting in a denial of service. (CVE-2022-20771)
Michał Dardas discovered that ClamAV incorrectly handled parsing HTML
files. A remote attacker could possibly use this issue to cause ClamAV to
consume resources, resulting in a denial of service. (CVE-2022-20785)
Michał Dardas discovered that ClamAV incorrectly handled loading the
signature database. A remote attacker could possibly use this issue
Ubuntu
ClamAV vulnerabilities
vendor_ubuntu·2022-05-17·CVSS 8.6
CVE-2022-20770 [HIGH] ClamAV vulnerabilities
Title: ClamAV vulnerabilities
Summary: Several security issues were fixed in ClamAV.
Michał Dardas discovered that ClamAV incorrectly handled parsing CHM files.
A remote attacker could possibly use this issue to cause ClamAV to stop
responding, resulting in a denial of service. (CVE-2022-20770)
Michał Dardas discovered that ClamAV incorrectly handled parsing TIFF
files. A remote attacker could possibly use this issue to cause ClamAV to
stop responding, resulting in a denial of service. (CVE-2022-20771)
Michał Dardas discovered that ClamAV incorrectly handled parsing HTML
files. A remote attacker could possibly use this issue to cause ClamAV to
consume resources, resulting in a denial of service. (CVE-2022-20785)
Michał Dardas discovered that ClamAV incorrectly handled loading the
sign
Ubuntu
ClamAV vulnerabilities
vendor_ubuntu·2022-05-17·CVSS 8.6
CVE-2022-20771 [HIGH] ClamAV vulnerabilities
Title: ClamAV vulnerabilities
Summary: Several security issues were fixed in ClamAV.
USN-5423-1 fixed several vulnerabilities in ClamAV. This update provides
the corresponding update for Ubuntu 14.04 ESM and 16.04 ESM.
Original advisory details:
Michał Dardas discovered that ClamAV incorrectly handled parsing CHM files.
A remote attacker could possibly use this issue to cause ClamAV to stop
responding, resulting in a denial of service. (CVE-2022-20770)
Michał Dardas discovered that ClamAV incorrectly handled parsing TIFF
files. A remote attacker could possibly use this issue to cause ClamAV to
stop responding, resulting in a denial of service. (CVE-2022-20771)
Michał Dardas discovered that ClamAV incorrectly handled parsing HTML
files. A remote attacker could possibly use this issue
Debian
CVE-2022-20792: clamav - A vulnerability in the regex module used by the signature database load module o...
vendor_debian·2022·CVSS 7.8
CVE-2022-20792 [HIGH] CVE-2022-20792: clamav - A vulnerability in the regex module used by the signature database load module o...
A vulnerability in the regex module used by the signature database load module of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior versions could allow an authenticated, local attacker to crash ClamAV at database load time, and possibly gain code execution. The vulnerability is due to improper bounds checking that may result in a multi-byte heap buffer overwflow write. An attacker could exploit this vulnerability by placing a crafted CDB ClamAV signature database file in the ClamAV database directory. An exploit could allow the attacker to run code as the clamav user.
Scope: local
bookworm: resolved (fixed in 0.103.6+dfsg-1)
bullseye: resolved (fixed in 0.103.6+dfsg-0+deb11u1)
forky: resolved (fixed in 0.103.6+dfsg-1)
sid: resolved (fixed in 0.103.
Cisco
Cisco TelePresence Collaboration Endpoint and RoomOS Software Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2022-20792 Cisco TelePresence Collaboration Endpoint and RoomOS Software Vulnerabilities
CVE-2022-20792: Cisco TelePresence Collaboration Endpoint and RoomOS Software Vulnerabilities
Multiple vulnerabilities in the web engine of Cisco Telepresence CE Software and RoomOS Software could allow a remote attacker to cause a denial of service (DoS) condition, redirect users to an attacker controlled destination or view sensitive data on an affected device. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-601, CWE-84, CWE-601, CWE-84
Bug IDs: CSCvw11997, CSCvw12003, CSCvw12005, CSCvw12003, CSCvw11997
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-08-10
Published