Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-20803
HistoryFeb 17, 2023 - 6:15 p.m.

Double free

2023-02-1718:15:00
PRIOn knowledge base
www.prio-n.com
10
clamav
ole2 file parser
vulnerability
denial of service
remote attacker
double-free
crafted file
exploit

7.2 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

55.5%

A vulnerability in the OLE2 file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device.The vulnerability is due to incorrect use of the realloc function that may result in a double-free. An attacker could exploit this vulnerability by submitting a crafted OLE2 file to be scanned by ClamAV on the affected device. An exploit could allow the attacker to cause the ClamAV scanning process to crash, resulting in a denial of service condition.

CPENameOperatorVersion
clamavge0.104.0
clamavlt0.104.3

7.2 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

55.5%