Security News > 2023 > February > Antivirus apps are there to protect you – Cisco's ClamAV has a heckuva flaw

Antivirus apps are there to protect you – Cisco's ClamAV has a heckuva flaw
2023-02-17 06:02

Cisco's open source ClamAV can fill that role - once you patch the 9.8/10 rated arbitrary code execution flaw the networking giant revealed on Wednesday.

"A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to execute arbitrary code," states Cisco's security advisory, which identifies the issue as CVE-2023-20032.

"An attacker could exploit this vulnerability by submitting a crafted HFS+ partition file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to execute arbitrary code with the privileges of the ClamAV scanning process, or else crash the process, resulting in a denial of service condition."

ClamAV's blog reveals a second flaw in the software: CVE-2023-20052.

The Secure Endpoint Private Cloud also needs a fix, as does Cisco's Secure Endpoint product for Linux, Windows, and macOS. Thankfully, Cisco is not aware of "Any public announcements or malicious use of the vulnerability that is described in this advisory."

What with ClamAV being free and open source, these flaws will likely be a target that miscreants and criminals won't ignore for long.


News URL

https://go.theregister.com/feed/www.theregister.com/2023/02/17/cisco_clamav_critical_flaw/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2023-03-01 CVE-2023-20052 XML Entity Expansion vulnerability in multiple products
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to access sensitive information on an affected device. This vulnerability is due to enabling XML entity substitution that may result in XML external entity injection.
network
low complexity
cisco clamav stormshield CWE-776
5.3
2023-03-01 CVE-2023-20032 Out-of-bounds Write vulnerability in multiple products
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to execute arbitrary code. This vulnerability is due to a missing buffer size check that may result in a heap buffer overflow write.
network
low complexity
cisco clamav stormshield CWE-787
critical
9.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Clamav 1 1 18 22 7 48