It was discovered that ClamAV incorrectly handled parsing certain OLE2 files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2024-20290)
Amit Schendel discovered that the ClamAV ClamD service incorrectly handled the VirusEvent feature. An attacker able to connect to ClamD could possibly use this issue to execute arbitrary code. (CVE-2024-20328)
{ "availability": "No subscription required", "binaries": [ { "binary_name": "clamav", "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1" }, { "binary_name": "clamav-base", "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1" }, { "binary_name": "clamav-daemon", "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1" }, { "binary_name": "clamav-daemon-dbgsym", "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1" }, { "binary_name": "clamav-dbgsym", "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1" }, { "binary_name": "clamav-docs", "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1" }, { "binary_name": "clamav-freshclam", "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1" }, { "binary_name": "clamav-freshclam-dbgsym", "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1" }, { "binary_name": "clamav-milter", "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1" }, { "binary_name": "clamav-milter-dbgsym", "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1" }, { "binary_name": "clamav-testfiles", "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1" }, { "binary_name": "clamdscan", "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1" }, { "binary_name": "clamdscan-dbgsym", "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1" }, { "binary_name": "libclamav-dev", "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1" }, { "binary_name": "libclamav11", "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1" }, { "binary_name": "libclamav11-dbgsym", "binary_version": "1.0.5+dfsg-0ubuntu0.23.10.1" } ] }