CVE Vulnerabilities

CVE-2022-20771

Published: May 04, 2022 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in the TIFF file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. For a description of this vulnerability, see the ClamAV blog. This advisory will be updated as additional information becomes available.

Affected Software

NameVendorStart VersionEnd Version
ClamavClamav*0.103.5 (including)
ClamavClamav0.104.0 (including)0.104.2 (including)
ClamavUbuntubionic*
ClamavUbuntudevel*
ClamavUbuntuesm-infra-legacy/trusty*
ClamavUbuntuesm-infra/bionic*
ClamavUbuntuesm-infra/focal*
ClamavUbuntuesm-infra/xenial*
ClamavUbuntufocal*
ClamavUbuntuimpish*
ClamavUbuntujammy*
ClamavUbuntukinetic*
ClamavUbuntutrusty/esm*
ClamavUbuntuupstream*

References