It was discovered that ClamAV incorrectly handled parsing certain OLE2 files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2024-20290)
Amit Schendel discovered that the ClamAV ClamD service incorrectly handled the VirusEvent feature. An attacker able to connect to ClamD could possibly use this issue to execute arbitrary code. (CVE-2024-20328)
{
"binaries": [
{
"binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
"binary_name": "clamav"
},
{
"binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
"binary_name": "clamav-base"
},
{
"binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
"binary_name": "clamav-daemon"
},
{
"binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
"binary_name": "clamav-daemon-dbgsym"
},
{
"binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
"binary_name": "clamav-dbgsym"
},
{
"binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
"binary_name": "clamav-docs"
},
{
"binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
"binary_name": "clamav-freshclam"
},
{
"binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
"binary_name": "clamav-freshclam-dbgsym"
},
{
"binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
"binary_name": "clamav-milter"
},
{
"binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
"binary_name": "clamav-milter-dbgsym"
},
{
"binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
"binary_name": "clamav-testfiles"
},
{
"binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
"binary_name": "clamdscan"
},
{
"binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
"binary_name": "clamdscan-dbgsym"
},
{
"binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
"binary_name": "libclamav-dev"
},
{
"binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
"binary_name": "libclamav11"
},
{
"binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1",
"binary_name": "libclamav11-dbgsym"
}
],
"availability": "No subscription required"
}