CVE-2022-20770
HIGHClamAV < 0.103.5 and 0.104.0-0.104.2 - Unauthenticated Denial of Service in CHM File Parser
Title source: llmDescription
On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in CHM file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. For a description of this vulnerability, see the ClamAV blog. This advisory will be updated as additional information becomes available.
References (6)
Core 6
Core References
Third Party Advisory vendor-advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-dos-prVGcHLd
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7RV6BLIATIJE74SQ6NG5ZC4JK5MMDQ2R/
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N4NNBIJVG6Z4PDIKUZXTYXICYUAYAZ56/
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BX5ZXNHP4NFYQ5BFSKY3WT7NTBZUYG7L/
Mailing List, Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2022/06/msg00004.html
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/202310-01
Scores
CVSS v3
8.6
EPSS
0.0086
EPSS Percentile
75.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-399
Status
published
Products (9)
cisco/secure_endpoint
< 1.16.3
cisco/secure_endpoint
< 1.17.2
cisco/secure_endpoint
< 7.5.5
clamav/clamav
< 0.103.5
clamav/clamav
0.104.0 - 0.104.2
debian/debian_linux
9.0
fedoraproject/fedora
34
fedoraproject/fedora
35
fedoraproject/fedora
36
Published
May 04, 2022
Tracked Since
Feb 18, 2026