Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.rc > #382413 > unrolled thread

Bug#1093880: clamav: CVE-2025-20128

Started byMoritz Mühlenhoff <jmm@inutil.org>
First post2025-01-23 20:10 +0100
Last post2025-02-06 23:10 +0100
Articles 2 — 2 participants

Back to article view | Back to linux.debian.bugs.rc


Contents

  Bug#1093880: clamav: CVE-2025-20128 Moritz Mühlenhoff <jmm@inutil.org> - 2025-01-23 20:10 +0100
    Bug#1093880: marked as done (clamav: CVE-2025-20128) "Debian Bug Tracking System" <owner@bugs.debian.org> - 2025-02-06 23:10 +0100

#382413 — Bug#1093880: clamav: CVE-2025-20128

FromMoritz Mühlenhoff <jmm@inutil.org>
Date2025-01-23 20:10 +0100
SubjectBug#1093880: clamav: CVE-2025-20128
Message-ID<K8aKu-bhtR-27@gated-at.bofh.it>
Source: clamav
X-Debbugs-CC: team@security.debian.org
Severity: grave
Tags: security

Hi,

The following vulnerability was published for clamav.

CVE-2025-20128[0]:
| A vulnerability in the Object Linking and Embedding 2 (OLE2)
| decryption routine of ClamAV could allow an unauthenticated, remote
| attacker to cause a denial of service (DoS) condition on an affected
| device.    This vulnerability is due to an integer underflow in a
| bounds check that allows for a heap buffer overflow read. An
| attacker could exploit this vulnerability by submitting a crafted
| file containing OLE2 content to be scanned by ClamAV on an affected
| device. A successful exploit could allow the attacker to terminate
| the ClamAV scanning process, resulting in a DoS condition on the
| affected software.  For a description of this vulnerability, see the
| .  Cisco has released software updates that address this
| vulnerability. There are no workarounds that address this
| vulnerability.

https://blog.clamav.net/2025/01/clamav-142-and-108-security-patch.html


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2025-20128
    https://www.cve.org/CVERecord?id=CVE-2025-20128

Please adjust the affected versions in the BTS as needed.

[toc] | [next] | [standalone]


#383709 — Bug#1093880: marked as done (clamav: CVE-2025-20128)

From"Debian Bug Tracking System" <owner@bugs.debian.org>
Date2025-02-06 23:10 +0100
SubjectBug#1093880: marked as done (clamav: CVE-2025-20128)
Message-ID<Kdiel-eWp8-11@gated-at.bofh.it>
In reply to#382413

[Multipart message — attachments visible in raw view] — view raw

Your message dated Thu, 06 Feb 2025 22:06:05 +0000
with message-id <E1tgA0b-00EBvf-47@fasolo.debian.org>
and subject line Bug#1093880: fixed in clamav 1.4.2+dfsg-1
has caused the Debian Bug report #1093880,
regarding clamav: CVE-2025-20128
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
1093880: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1093880
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.bugs.rc


csiph-web