CVE-2022-20792
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the regex module used by the signature database load module of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior versions could allow an authenticated, local attacker to crash ClamAV at database load time, and possibly gain code execution. The vulnerability is due to improper bounds checking that may result in a multi-byte heap buffer overwflow write. An attacker could exploit this vulnerability by placing a crafted CDB ClamAV signature database file in the ClamAV database directory. An exploit could allow the attacker to run code as the clamav user.
Una vulnerabilidad en el módulo regex usado por el módulo de carga de la base de datos de firmas de Clam AntiVirus (ClamAV) versiones 0.104.0 hasta 0.104.2 y LTS versiones 0.103.5 y anteriores, podría permitir a un atacante local autenticado bloquear ClamAV en el momento de la carga de la base de datos, y posiblemente obtener una ejecución de código. La vulnerabilidad es debido a una comprobación inapropiada de límites que puede resultar en una escritura de desbordamiento del búfer de la pila de varios bytes. Un atacante podría explotar esta vulnerabilidad al colocar un archivo de base de datos de firmas CDB ClamAV diseñado en el directorio de la base de datos de ClamAV. Una explotación podría permitir al atacante ejecutar código como el usuario clamav
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2021-11-02 CVE Reserved
- 2022-05-17 CVE Published
- 2024-01-21 EPSS Updated
- 2024-11-01 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-125: Out-of-bounds Read
- CWE-787: Out-of-bounds Write
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://blog.clamav.net/2022/05/clamav-01050-01043-01036-released.html | 2023-10-01 | |
https://security.gentoo.org/glsa/202310-01 | 2023-10-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | <= 0.103.5 Search vendor "Clamav" for product "Clamav" and version " <= 0.103.5" | - |
Affected
| ||||||
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | >= 0.104.0 <= 0.104.2 Search vendor "Clamav" for product "Clamav" and version " >= 0.104.0 <= 0.104.2" | - |
Affected
|