Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-20216

Опубликовано: 01 июл. 2026
Источник: redhat
CVSS3: 7.5

Описание

A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper handling of temporary resources during file scanning. An attacker could exploit this vulnerability by submitting a crafted InstallShield file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process and temporarily consume available system resources, resulting in a DoS condition on the affected software.

A flaw was found in ClamAV's InstallShield file format parser. An unauthenticated, remote attacker could exploit this vulnerability by submitting a specially crafted InstallShield file for scanning. This improper handling of temporary resources during file scanning could lead to the termination of the ClamAV scanning process and temporary consumption of system resources, resulting in a Denial of Service (DoS) condition on the affected device.

Отчет

ClamAV, when deployed in Red Hat environments, is often used for scanning untrusted files. This Important flaw allows an unauthenticated, remote attacker to cause a denial of service by submitting a specially crafted InstallShield file. Successful exploitation can lead to the ClamAV scanning process terminating and consuming system resources, impacting the availability of the scanning service.

Меры по смягчению последствий

To reduce the risk of denial of service, deploy ClamAV within a sandboxed environment to contain potential resource exhaustion. Additionally, exercise caution when processing untrusted InstallShield files, and restrict their sources to trusted origins where possible.

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2496115ClamAV: ClamAV: Denial of Service via crafted InstallShield file

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper handling of temporary resources during file scanning. An attacker could exploit this vulnerability by submitting a crafted InstallShield file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process and temporarily consume available system resources, resulting in a DoS condition on the affected software.

CVSS3: 7.5
nvd
около 1 месяца назад

A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper handling of temporary resources during file scanning. An attacker could exploit this vulnerability by submitting a crafted InstallShield file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process and temporarily consume available system resources, resulting in a DoS condition on the affected software.

CVSS3: 7.5
msrc
24 дня назад

ClamAV InstallShield File Format Processing Resource Exhaustion Vulnerability

CVSS3: 7.5
debian
около 1 месяца назад

A vulnerability in the InstallShield file format parser of ClamAV coul ...

CVSS3: 7.5
github
около 1 месяца назад

A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper handling of temporary resources during file scanning. An attacker could exploit this vulnerability by submitting a crafted InstallShield file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process and temporarily consume available system resources, resulting in a DoS condition on the affected software.

7.5 High

CVSS3