SB2020051328 - Out-of-bounds read in clamav (Alpine package)
Published: May 13, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2020-3327)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition when processing ARJ archives. A remote attacker can pass specially crafted ARJ archive to the application, trigger out-of-bounds read error and crash the service.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=08accee45c774482278c0007d73ec978f6e1e9f9
- https://git.alpinelinux.org/aports/commit/?id=f468b1fb3fb7fe47bc6f66d5096d8dcffe858265
- https://git.alpinelinux.org/aports/commit/?id=8e39ea63fd40571929d4d61e03a300bb9339d870
- https://git.alpinelinux.org/aports/commit/?id=a9ebb46fcdc0b751dfd164df179fe819bce92722