7.5
CVSSv3

CVE-2020-3123

Published: 05/02/2020 Updated: 01/01/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A vulnerability in the Data-Loss-Prevention (DLP) module in Clam AntiVirus (ClamAV) Software versions 0.102.1 and 0.102.0 could allow an unauthenticated, remote malicious user to cause a denial of service condition on an affected device. The vulnerability is due to an out-of-bounds read affecting users that have enabled the optional DLP feature. An attacker could exploit this vulnerability by sending a crafted email file to an affected device. An exploit could allow the malicious user to cause the ClamAV scanning process crash, resulting in a denial of service condition.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

clamav clamav 0.102.0

clamav clamav 0.102.1

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

canonical ubuntu linux 19.10

Vendor Advisories

Debian Bug report logs - #950944 clamav: Vulnerability in the Data-Loss-Prevention (DLP) module Package: clamav; Maintainer for clamav is ClamAV Team <pkg-clamav-devel@listsaliothdebianorg>; Source for clamav is src:clamav (PTS, buildd, popcon) Reported by: Scott Kitterman <debian@kittermancom> Date: Sat, 8 Feb ...
ClamAV could be made to crash if it opened a specially crafted file ...
ClamAV could be made to crash if it opened a specially crafted file ...
A denial-of-service (DoS) condition may occur when using the optional credit card data-loss-prevention (DLP) feature Improper bounds checking of an unsigned variable resulted in an out-of-bounds read, which causes a crash ...