Severity
5.3MEDIUM
EPSS
5.7%
top 9.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 1
Latest updateMar 3

Description

On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to access sensitive information on an affected device. This vulnerability is due to enabling XML entity substitution that may result in XML external entity injection. An attacker could exploit this vulnerability by submitting a crafted DMG

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages7 packages

Debianclamav< 0.103.8+dfsg-0+deb11u1+3
Ubuntuclamav< 0.103.8+dfsg-0ubuntu0.18.04.1+4
NVDclamav/clamav0.104.00.105.1+2
NVDcisco/secure_endpoint8.0.1.211608.1.5+3

🔴Vulnerability Details

4
OSV
CVE-2023-20052: On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 12023-03-01
GHSA
GHSA-pcr4-7r58-755h: On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 12023-03-01
OSV
clamav vulnerabilities2023-02-27
CVEList
CVE-2023-20052: On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 12023-02-16

📋Vendor Advisories

4
Ubuntu
ClamAV vulnerabilities2023-02-27
Cisco
ClamAV DMG File Parsing XML Entity Expansion Vulnerability Affecting Cisco Products: February 20232023-02-15
Microsoft
On Feb 15 2023 the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier 0.105.1 and earlier and 0.103.2023-02-14
Debian
CVE-2023-20052: clamav - On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was ...2023

🕵️Threat Intelligence

2
Sentinelone
CVE-2023-20052: ClamAV XXE Vulnerability2023-03-03
Sentinelone
CVE-2023-20052: ClamAV XXE Vulnerability2023-03-03
CVE-2023-20052 (MEDIUM CVSS 5.3) | On Feb 15 | cvebase.io