Out-of-bounds read in ClamAV - CVE-2025-20234
Published: June 18, 2025
Vulnerability details
The vulnerability allows a remote attacker to gain access to perform a denial of service attack.
The vulnerability exists due to a boundary condition when handling UDF files. A remote attacker can pass a specially crafted UDF file to the application, trigger an out-of-bounds read error and read contents of memory on the system or perform a denial of service (DoS) attack.
Affected software
Secure Endpoint Connector for Mac
Secure Endpoint Connector for Linux
Secure Endpoint Private Cloud
Secure Endpoint Connector for Windows
Fedora
Ubuntu
RSA Authentication Manager
clamav
clamav (Ubuntu package)
squidclamav
How to mitigate CVE-2025-20234
RSA Authentication Manager - update to 8.8 Patch 2
clamav - addressed in versions 1.0.9-1.el8, 1.0.9-1.el9, 1.0.9-1.fc41, 1.4.3-1.el10_1
clamav (Ubuntu package) - addressed in versions 1.4.3+dfsg-0ubuntu0.20.04.1+esm1, 1.4.3+dfsg-0ubuntu0.22.04.1, 1.4.3+dfsg-0ubuntu0.24.04.1, 1.4.3+dfsg-0ubuntu0.24.10.1, 1.4.3+dfsg-0ubuntu0.25.04.1
Secure Endpoint Connector for Mac - update to 1.26.1
Secure Endpoint Connector for Linux - update to 1.26.1
Secure Endpoint Private Cloud - update to 4.2.2
squidclamav - addressed in versions 7.5-1.el8, 7.5-1.el9
Secure Endpoint Connector for Windows - addressed in versions 7.5.21, 8.4.5
External References
Related Security Bulletins
- Multiple vulnerabilities in ClamAV
- Cisco Secure Endpoint Connectors update for ClamAV
- Fedora EPEL 8 update for clamav
- Fedora 41 update for clamav
- Fedora EPEL 9 update for clamav
- Fedora EPEL 10.1 update for clamav
- Ubuntu update for clamav
- Ubuntu update for clamav
- RSA Authentication Manager update for third-party components
- Fedora EPEL 8 update for squidclamav
- Fedora EPEL 9 update for squidclamav