CVE-2020-3327

A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a heap buffer overflow read. An attacker could exploit this vulnerability by sending a crafted ARJ file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process crash, resulting in a denial of service condition.
References
Link Resource
https://blog.clamav.net/2020/05/clamav-01023-security-patch-released.html Vendor Advisory
https://lists.debian.org/debian-lts-announce/2020/05/msg00018.html Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2020/08/msg00010.html Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3BMTC7I5LGY4FCIZLHPNC4WWC6VNLFER/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IJ67VH37NCG25PICGWFWZHSVG7PBT7MC/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L5YWYT27SBTV4RZSGFHIQUI4LQVFASWS/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QM7EXJHDEZJLWM2NKH6TCDXOBP5NNYIN/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ROBJOGJOT44MVDX7RQEACYHQN4LYW5RK/
https://security.gentoo.org/glsa/202007-23 Third Party Advisory
https://usn.ubuntu.com/4370-1/ Third Party Advisory
https://usn.ubuntu.com/4370-2/ Third Party Advisory
https://usn.ubuntu.com/4435-1/ Third Party Advisory
https://usn.ubuntu.com/4435-2/ Third Party Advisory
https://blog.clamav.net/2020/05/clamav-01023-security-patch-released.html Vendor Advisory
https://lists.debian.org/debian-lts-announce/2020/05/msg00018.html Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2020/08/msg00010.html Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3BMTC7I5LGY4FCIZLHPNC4WWC6VNLFER/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IJ67VH37NCG25PICGWFWZHSVG7PBT7MC/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L5YWYT27SBTV4RZSGFHIQUI4LQVFASWS/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QM7EXJHDEZJLWM2NKH6TCDXOBP5NNYIN/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ROBJOGJOT44MVDX7RQEACYHQN4LYW5RK/
https://security.gentoo.org/glsa/202007-23 Third Party Advisory
https://usn.ubuntu.com/4370-1/ Third Party Advisory
https://usn.ubuntu.com/4370-2/ Third Party Advisory
https://usn.ubuntu.com/4435-1/ Third Party Advisory
https://usn.ubuntu.com/4435-2/ Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:cisco:clam_antivirus:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*

History

21 Nov 2024, 05:30

Type Values Removed Values Added
References () https://blog.clamav.net/2020/05/clamav-01023-security-patch-released.html - Vendor Advisory () https://blog.clamav.net/2020/05/clamav-01023-security-patch-released.html - Vendor Advisory
References () https://lists.debian.org/debian-lts-announce/2020/05/msg00018.html - Mailing List, Third Party Advisory () https://lists.debian.org/debian-lts-announce/2020/05/msg00018.html - Mailing List, Third Party Advisory
References () https://lists.debian.org/debian-lts-announce/2020/08/msg00010.html - Mailing List, Third Party Advisory () https://lists.debian.org/debian-lts-announce/2020/08/msg00010.html - Mailing List, Third Party Advisory
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3BMTC7I5LGY4FCIZLHPNC4WWC6VNLFER/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3BMTC7I5LGY4FCIZLHPNC4WWC6VNLFER/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IJ67VH37NCG25PICGWFWZHSVG7PBT7MC/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IJ67VH37NCG25PICGWFWZHSVG7PBT7MC/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L5YWYT27SBTV4RZSGFHIQUI4LQVFASWS/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L5YWYT27SBTV4RZSGFHIQUI4LQVFASWS/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QM7EXJHDEZJLWM2NKH6TCDXOBP5NNYIN/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QM7EXJHDEZJLWM2NKH6TCDXOBP5NNYIN/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ROBJOGJOT44MVDX7RQEACYHQN4LYW5RK/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ROBJOGJOT44MVDX7RQEACYHQN4LYW5RK/ -
References () https://security.gentoo.org/glsa/202007-23 - Third Party Advisory () https://security.gentoo.org/glsa/202007-23 - Third Party Advisory
References () https://usn.ubuntu.com/4370-1/ - Third Party Advisory () https://usn.ubuntu.com/4370-1/ - Third Party Advisory
References () https://usn.ubuntu.com/4370-2/ - Third Party Advisory () https://usn.ubuntu.com/4370-2/ - Third Party Advisory
References () https://usn.ubuntu.com/4435-1/ - Third Party Advisory () https://usn.ubuntu.com/4435-1/ - Third Party Advisory
References () https://usn.ubuntu.com/4435-2/ - Third Party Advisory () https://usn.ubuntu.com/4435-2/ - Third Party Advisory

07 Nov 2023, 03:22

Type Values Removed Values Added
References
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3BMTC7I5LGY4FCIZLHPNC4WWC6VNLFER/', 'name': 'FEDORA-2020-b0acd7b66e', 'tags': ['Mailing List', 'Third Party Advisory'], 'refsource': 'FEDORA'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QM7EXJHDEZJLWM2NKH6TCDXOBP5NNYIN/', 'name': 'FEDORA-2020-dd0c20d985', 'tags': ['Mailing List', 'Third Party Advisory'], 'refsource': 'FEDORA'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IJ67VH37NCG25PICGWFWZHSVG7PBT7MC/', 'name': 'FEDORA-2020-6584a641ae', 'tags': ['Mailing List', 'Third Party Advisory'], 'refsource': 'FEDORA'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ROBJOGJOT44MVDX7RQEACYHQN4LYW5RK/', 'name': 'FEDORA-2020-d98d2cbae1', 'tags': ['Mailing List', 'Third Party Advisory'], 'refsource': 'FEDORA'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L5YWYT27SBTV4RZSGFHIQUI4LQVFASWS/', 'name': 'FEDORA-2020-bca44487a1', 'tags': ['Mailing List', 'Third Party Advisory'], 'refsource': 'FEDORA'}
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L5YWYT27SBTV4RZSGFHIQUI4LQVFASWS/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QM7EXJHDEZJLWM2NKH6TCDXOBP5NNYIN/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IJ67VH37NCG25PICGWFWZHSVG7PBT7MC/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ROBJOGJOT44MVDX7RQEACYHQN4LYW5RK/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3BMTC7I5LGY4FCIZLHPNC4WWC6VNLFER/ -

Information

Published : 2020-05-13 03:15

Updated : 2024-11-21 05:30


NVD link : CVE-2020-3327

Mitre link : CVE-2020-3327

CVE.ORG link : CVE-2020-3327


JSON object : View

Products Affected

cisco

  • clam_antivirus

debian

  • debian_linux

fedoraproject

  • fedora

canonical

  • ubuntu_linux
CWE
CWE-20

Improper Input Validation