USN-6636-1

Source
https://ubuntu.com/security/notices/USN-6636-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6636-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-6636-1
Related
Published
2024-02-14T16:11:25.366081Z
Modified
2024-02-14T16:11:25.366081Z
Summary
clamav vulnerabilities
Details

It was discovered that ClamAV incorrectly handled parsing certain OLE2 files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2024-20290)

Amit Schendel discovered that the ClamAV ClamD service incorrectly handled the VirusEvent feature. An attacker able to connect to ClamD could possibly use this issue to execute arbitrary code. (CVE-2024-20328)

References

Affected packages

Ubuntu:23.10 / clamav

Package

Name
clamav
Purl
pkg:deb/ubuntu/clamav?arch=src?distro=mantic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.5+dfsg-0ubuntu0.23.10.1

Affected versions

0.*

0.103.8+dfsg-0ubuntu1
0.103.8+dfsg-0ubuntu2

1.*

1.0.2+dfsg-1ubuntu1
1.0.4+dfsg-0ubuntu0.23.10.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
            "binary_name": "clamav"
        },
        {
            "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
            "binary_name": "clamav-base"
        },
        {
            "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
            "binary_name": "clamav-daemon"
        },
        {
            "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
            "binary_name": "clamav-daemon-dbgsym"
        },
        {
            "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
            "binary_name": "clamav-dbgsym"
        },
        {
            "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
            "binary_name": "clamav-docs"
        },
        {
            "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
            "binary_name": "clamav-freshclam"
        },
        {
            "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
            "binary_name": "clamav-freshclam-dbgsym"
        },
        {
            "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
            "binary_name": "clamav-milter"
        },
        {
            "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
            "binary_name": "clamav-milter-dbgsym"
        },
        {
            "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
            "binary_name": "clamav-testfiles"
        },
        {
            "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
            "binary_name": "clamdscan"
        },
        {
            "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
            "binary_name": "clamdscan-dbgsym"
        },
        {
            "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
            "binary_name": "libclamav-dev"
        },
        {
            "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
            "binary_name": "libclamav11"
        },
        {
            "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
            "binary_name": "libclamav11-dbgsym"
        }
    ]
}