Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.rc > #382413 > unrolled thread
| Started by | Moritz Mühlenhoff <jmm@inutil.org> |
|---|---|
| First post | 2025-01-23 20:10 +0100 |
| Last post | 2025-02-06 23:10 +0100 |
| Articles | 2 — 2 participants |
Back to article view | Back to linux.debian.bugs.rc
Bug#1093880: clamav: CVE-2025-20128 Moritz Mühlenhoff <jmm@inutil.org> - 2025-01-23 20:10 +0100
Bug#1093880: marked as done (clamav: CVE-2025-20128) "Debian Bug Tracking System" <owner@bugs.debian.org> - 2025-02-06 23:10 +0100
| From | Moritz Mühlenhoff <jmm@inutil.org> |
|---|---|
| Date | 2025-01-23 20:10 +0100 |
| Subject | Bug#1093880: clamav: CVE-2025-20128 |
| Message-ID | <K8aKu-bhtR-27@gated-at.bofh.it> |
Source: clamav
X-Debbugs-CC: team@security.debian.org
Severity: grave
Tags: security
Hi,
The following vulnerability was published for clamav.
CVE-2025-20128[0]:
| A vulnerability in the Object Linking and Embedding 2 (OLE2)
| decryption routine of ClamAV could allow an unauthenticated, remote
| attacker to cause a denial of service (DoS) condition on an affected
| device. This vulnerability is due to an integer underflow in a
| bounds check that allows for a heap buffer overflow read. An
| attacker could exploit this vulnerability by submitting a crafted
| file containing OLE2 content to be scanned by ClamAV on an affected
| device. A successful exploit could allow the attacker to terminate
| the ClamAV scanning process, resulting in a DoS condition on the
| affected software. For a description of this vulnerability, see the
| . Cisco has released software updates that address this
| vulnerability. There are no workarounds that address this
| vulnerability.
https://blog.clamav.net/2025/01/clamav-142-and-108-security-patch.html
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2025-20128
https://www.cve.org/CVERecord?id=CVE-2025-20128
Please adjust the affected versions in the BTS as needed.
[toc] | [next] | [standalone]
| From | "Debian Bug Tracking System" <owner@bugs.debian.org> |
|---|---|
| Date | 2025-02-06 23:10 +0100 |
| Subject | Bug#1093880: marked as done (clamav: CVE-2025-20128) |
| Message-ID | <Kdiel-eWp8-11@gated-at.bofh.it> |
| In reply to | #382413 |
[Multipart message — attachments visible in raw view] — view raw
Your message dated Thu, 06 Feb 2025 22:06:05 +0000 with message-id <E1tgA0b-00EBvf-47@fasolo.debian.org> and subject line Bug#1093880: fixed in clamav 1.4.2+dfsg-1 has caused the Debian Bug report #1093880, regarding clamav: CVE-2025-20128 to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact owner@bugs.debian.org immediately.) -- 1093880: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1093880 Debian Bug Tracking System Contact owner@bugs.debian.org with problems
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.bugs.rc
csiph-web