NA

CVE-2023-20197

Published: 16/08/2023 Updated: 25/01/2024
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote malicious user to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for completion when a file is decompressed, which may result in a loop condition that could cause the affected software to stop responding. An attacker could exploit this vulnerability by submitting a crafted HFS+ filesystem image to be scanned by ClamAV on an affected device. A successful exploit could allow the malicious user to cause the ClamAV scanning process to stop responding, resulting in a DoS condition on the affected software and consuming available system resources. For a description of this vulnerability, see the ClamAV blog .

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco secure endpoint private cloud

cisco secure endpoint

fedoraproject fedora 38

Vendor Advisories

Debian Bug report logs - #1050057 clamav: CVE-2023-20197 CVE-2023-20212 Package: src:clamav; Maintainer for src:clamav is ClamAV Team <pkg-clamav-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 19 Aug 2023 04:39:02 UTC Severity: important Tags: security, upstream Foun ...
A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device This vulnerability is due to an incorrect check for completion when a file is decompressed, which may result in a loop condition that c ...
A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device This vulnerability is due to an incorrect check for completion when a file is decompressed, which may result in a loop condition that c ...
A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device This vulnerability is due to an incorrect check for completion when a file is decompressed, which may result in a loop condition that co ...