Bugzilla – Bug 1223132
VUL-0: CVE-2024-20380: clamav: denial of service via HTML parser
Last modified: 2024-04-19 10:23:19 UTC
A vulnerability in the HTML parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to an issue in the C to Rust foreign function interface. An attacker could exploit this vulnerability by submitting a crafted file containing HTML content to be scanned by ClamAV on an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-20380 https://www.cve.org/CVERecord?id=CVE-2024-20380 https://blog.clamav.net/2024/04/clamav-131-123-106-patch-versions.html https://bugzilla.redhat.com/show_bug.cgi?id=2275998