ClamAV versions prior to 0.101.3 are susceptible to a zip bomb vulnerability where an unauthenticated attacker can cause a denial of service condition by sending crafted messages to an affected system.
The product does not release or incorrectly releases a resource before it is made available for re-use.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Clamav | Clamav | * | 0.101.3 (excluding) |
Clamav | Ubuntu | bionic | * |
Clamav | Ubuntu | disco | * |
Clamav | Ubuntu | trusty | * |
Clamav | Ubuntu | trusty/esm | * |
Clamav | Ubuntu | upstream | * |
Clamav | Ubuntu | xenial | * |