Race condition in ClamAV products - CVE-2020-3350

 

Race condition in ClamAV products - CVE-2020-3350

Published: June 24, 2020


Vulnerability identifier: #VU29233
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3350
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a race condition in the endpoint software. A local user can exploit the race, gain elevated privileges and delete arbitrary files on the system.


Affected software

Cisco AMP for Endpoints Mac Connector Software
Cisco AMP for Endpoints Linux Connector Software
ClamAV
Amazon Linux AMI
Gentoo Linux
Fedora
Ubuntu
clamav (Alpine package)
clamav (Ubuntu package)
clamav
RSA Authentication Manager

How to mitigate CVE-2020-3350

Install updates from vendor's website.

Cisco AMP for Endpoints Mac Connector Software - update to 1.12.4
Cisco AMP for Endpoints Linux Connector Software - update to 1.12.4
ClamAV - addressed in versions 0.102.4, 0.103
clamav (Alpine package) - update to 0.102.4-r0
clamav (Ubuntu package) - addressed in versions 0.102.4+dfsg-0ubuntu0.12.04.1, 0.102.4+dfsg-0ubuntu0.14.04.1+esm1, 0.102.4+dfsg-0ubuntu0.16.04.1, 0.102.4+dfsg-0ubuntu0.18.04.1, 0.102.4+dfsg-0ubuntu0.20.04.1
clamav - addressed in versions 0.102.4-1.el7, 0.102.4-1.el8, 0.102.4-1.fc31, 0.102.4-1.fc32
RSA Authentication Manager - update to 8.5 Patch 3

External References

Related Security Bulletins