CVE-2024-20380
ClamAV HTML Parser Denial of Service Vulnerability
Severity
High 7.5
CVSS 3.1
Exploited
Not listed
EPSS
0.011
64.3th percentile
Discovered by
Third party
Vendor-published field
Published
Apr 18, 2024
Assigned by cisco
Description
A vulnerability in the HTML parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to an issue in the C to Rust foreign function interface. An attacker could exploit this vulnerability by submitting a crafted file containing HTML content to be scanned by ClamAV on an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Weakness: CWE-475
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | ClamAV | Endpoint / EDR | cna-assigner |
Vendor-reported products (2)
- Cisco · ClamAV
- cisco · clam_antivirus