CVE-2022-20770
Published May 4, 2022
Last updated a year ago
Overview
- Description
- On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in CHM file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. For a description of this vulnerability, see the ClamAV blog. This advisory will be updated as additional information becomes available.
- Source
- ykramarz@cisco.com
- NVD status
- Modified
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 7.8
- Impact score
- 6.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:N/A:C
Weaknesses
- nvd@nist.gov
- NVD-CWE-noinfo
- ykramarz@cisco.com
- CWE-399
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:clamav:clamav:*:*:*:*:lts:*:*:*", "vulnerable": true, "matchCriteriaId": "27ADFD65-7F57-461B-AD74-FF8F7950B5E1", "versionEndIncluding": "0.103.5" }, { "criteria": "cpe:2.3:a:clamav:clamav:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FEA3B921-70F0-455E-84F0-EA08498AEB4D", "versionEndIncluding": "0.104.2", "versionStartIncluding": "0.104.0" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:macos:*:*", "vulnerable": true, "matchCriteriaId": "2D18B72E-A39C-4355-880C-D8F56F69DEC1", "versionEndExcluding": "1.16.3" }, { "criteria": "cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:linux:*:*", "vulnerable": true, "matchCriteriaId": "7EB9082D-A730-4BC0-A7C3-FD41C9B90C62", "versionEndExcluding": "1.17.2" }, { "criteria": "cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:windows:*:*", "vulnerable": true, "matchCriteriaId": "941865DD-D900-4FF7-B94B-8A4849653E01", "versionEndExcluding": "7.5.5" }, { "criteria": "cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:linux:*:*", "vulnerable": true, "matchCriteriaId": "F3E65C72-96CF-445D-9A4C-ED82ED79882E", "versionEndExcluding": "1.18.2", "versionStartIncluding": "1.18.0" }, { "criteria": "cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:macos:*:*", "vulnerable": true, "matchCriteriaId": "30810C03-D9F9-4CD2-B276-11E9302F245C", "versionEndExcluding": "1.18.2", "versionStartIncluding": "1.18.0" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A930E247-0B43-43CB-98FF-6CE7B8189835" }, { "criteria": "cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "80E516C0-98A4-4ADE-B69F-66A772E2BAAA" }, { "criteria": "cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5C675112-476C-4D7C-BCB9-A2FB2D0BC9FD" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DEECE5FC-CACF-4496-A3E7-164736409252" } ], "operator": "OR" } ] } ]