Race condition in ClamAV products - CVE-2020-3350
Published: June 24, 2020
Vulnerability identifier: #VU29233
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3350
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a race condition in the endpoint software. A local user can exploit the race, gain elevated privileges and delete arbitrary files on the system.
Affected software
Cisco AMP for Endpoints Mac Connector Software
Cisco AMP for Endpoints Linux Connector Software
ClamAV
Amazon Linux AMI
Gentoo Linux
Fedora
Ubuntu
clamav (Alpine package)
clamav (Ubuntu package)
clamav
RSA Authentication Manager
Cisco AMP for Endpoints Linux Connector Software
ClamAV
Amazon Linux AMI
Gentoo Linux
Fedora
Ubuntu
clamav (Alpine package)
clamav (Ubuntu package)
clamav
RSA Authentication Manager
How to mitigate CVE-2020-3350
Install updates from vendor's website.
Cisco AMP for Endpoints Mac Connector Software - update to 1.12.4
Cisco AMP for Endpoints Linux Connector Software - update to 1.12.4
ClamAV - addressed in versions 0.102.4, 0.103
clamav (Alpine package) - update to 0.102.4-r0
clamav (Ubuntu package) - addressed in versions 0.102.4+dfsg-0ubuntu0.12.04.1, 0.102.4+dfsg-0ubuntu0.14.04.1+esm1, 0.102.4+dfsg-0ubuntu0.16.04.1, 0.102.4+dfsg-0ubuntu0.18.04.1, 0.102.4+dfsg-0ubuntu0.20.04.1
clamav - addressed in versions 0.102.4-1.el7, 0.102.4-1.el8, 0.102.4-1.fc31, 0.102.4-1.fc32
RSA Authentication Manager - update to 8.5 Patch 3
Cisco AMP for Endpoints Linux Connector Software - update to 1.12.4
ClamAV - addressed in versions 0.102.4, 0.103
clamav (Alpine package) - update to 0.102.4-r0
clamav (Ubuntu package) - addressed in versions 0.102.4+dfsg-0ubuntu0.12.04.1, 0.102.4+dfsg-0ubuntu0.14.04.1+esm1, 0.102.4+dfsg-0ubuntu0.16.04.1, 0.102.4+dfsg-0ubuntu0.18.04.1, 0.102.4+dfsg-0ubuntu0.20.04.1
clamav - addressed in versions 0.102.4-1.el7, 0.102.4-1.el8, 0.102.4-1.fc31, 0.102.4-1.fc32
RSA Authentication Manager - update to 8.5 Patch 3
External References
Related Security Bulletins
- Race condition in Cisco AMP for Endpoints and ClamAV
- Gentoo update for ClamAV
- Race condition in clamav (Alpine package)
- Amazon Linux AMI update for clamav
- Ubuntu update for clamav
- Ubuntu update for clamav
- Fedora 31 update for clamav
- Fedora 32 update for clamav
- Fedora EPEL 7 update for clamav
- Fedora EPEL 8 update for clamav
- RSA Authentication Manager update for third-party components