#VU103240 Heap-based buffer overflow in ClamAV - CVE-2025-20128
Published: January 22, 2025 / Updated: June 18, 2025
ClamAV
ClamAV
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error when decrypting OLE2 file format. A remote attacker can pass a specially crafted file to the application, trigger a heap-based buffer overflow and perform a denial of service (DoS) attack.