cbcvebase.
CVE-2024-20505
published 2024-09-04

CVE-2024-20505: A vulnerability in the PDF parsing module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2.x versions, 1.0.6 and prior versions…

PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.56%
42.7th percentile
A vulnerability in the PDF parsing module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2.x versions, 1.0.6 and prior versions, all 0.105.x versions, all 0.104.x versions, and 0.103.11 and all prior versions could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to an out of bounds read. An attacker could exploit this vulnerability by submitting a crafted PDF file to be scanned by ClamAV on an affected device. An exploit could allow the attacker to terminate the scanning process.

Affected

46 ranges· showing 25
VendorProductVersion rangeFixed in
ciscoclamav
ciscoclamav
ciscoclamav
ciscoclamav
ciscoclamav
ciscoclamav
ciscoclamav
ciscoclamav
ciscoclamav
ciscoclamav
ciscoclamav
ciscoclamav
ciscoclamav
ciscoclamav
ciscoclamav
ciscoclamav
ciscoclamav
ciscoclamav
ciscoclamav
ciscoclamav
ciscoclamav
ciscoclamav
ciscoclamav
ciscoclamav
clamavclamav< 0.103.120.103.12

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_msrc7.5HIGH
vendor_debian4.0MEDIUM
vendor_ubuntu4.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.