Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-20197


A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for completion when a file is decompressed, which may result in a loop condition that could cause the affected software to stop responding. An attacker could exploit this vulnerability by submitting a crafted HFS+ filesystem image to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to stop responding, resulting in a DoS condition on the affected software and consuming available system resources. For a description of this vulnerability, see the ClamAV blog .


Published

2023-08-16T22:15:10.510

Last Modified

2024-11-21T07:40:48.563

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-835
  • Type: Primary
    CWE-835

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco secure_endpoint < 1.22.0 Yes
Application cisco secure_endpoint < 1.22.0 Yes
Application cisco secure_endpoint < 7.5.13.21586 Yes
Application cisco secure_endpoint < 8.1.7.21585 Yes
Application cisco secure_endpoint_private_cloud < 3.8.0 Yes
Operating System fedoraproject fedora 38 Yes

References