Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-20380

Опубликовано: 18 апр. 2024
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

A vulnerability in the HTML parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to an issue in the C to Rust foreign function interface. An attacker could exploit this vulnerability by submitting a crafted file containing HTML content to be scanned by ClamAV on an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:clamav:clamav:1.3.0:-:*:*:*:*:*:*
cpe:2.3:a:clamav:clamav:1.3.0:rc:*:*:*:*:*:*
cpe:2.3:a:clamav:clamav:1.3.0:rc2:*:*:*:*:*:*

EPSS

Процентиль: 65%
0.005
Низкий

7.5 High

CVSS3

Дефекты

CWE-475

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 2 года назад

A vulnerability in the HTML parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to an issue in the C to Rust foreign function interface. An attacker could exploit this vulnerability by submitting a crafted file containing HTML content to be scanned by ClamAV on an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.

CVSS3: 7.5
debian
почти 2 года назад

A vulnerability in the HTML parser of ClamAV could allow an unauthenti ...

CVSS3: 7.5
github
почти 2 года назад

A vulnerability in the HTML parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to an issue in the C to Rust foreign function interface. An attacker could exploit this vulnerability by submitting a crafted file containing HTML content to be scanned by ClamAV on an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.

CVSS3: 7.5
fstec
почти 2 года назад

Уязвимость анализатора HTML-кода пакета антивирусных программ ClamAV, позволяющая нарушителю вызвать отказ в обслуживании

suse-cvrf
около 1 года назад

Security update for clamav

EPSS

Процентиль: 65%
0.005
Низкий

7.5 High

CVSS3

Дефекты

CWE-475