CVE-2022-20803
ClamAV Double-free Vulnerability in the OLE2 File Parser
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the OLE2 file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device.The vulnerability is due to incorrect use of the realloc function that may result in a double-free. An attacker could exploit this vulnerability by submitting a crafted OLE2 file to be scanned by ClamAV on the affected device. An exploit could allow the attacker to cause the ClamAV scanning process to crash, resulting in a denial of service condition.
Multiple vulnerabilities have been discovered in ClamAV, the worst of which could result in remote code execution. Versions greater than or equal to 0.103.7 are affected.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2021-11-02 CVE Reserved
- 2023-02-17 CVE Published
- 2024-10-28 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-415: Double Free
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://blog.clamav.net/2022/05/clamav-01050-01043-01036-released.html | 2023-10-01 | |
https://security.gentoo.org/glsa/202310-01 | 2023-10-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Clamav Search vendor "Clamav" | Clamav Search vendor "Clamav" for product "Clamav" | >= 0.104.0 < 0.104.3 Search vendor "Clamav" for product "Clamav" and version " >= 0.104.0 < 0.104.3" | - |
Affected
|