{"id":"MGASA-2020-0105","summary":"Updated clamav packages fix security vulnerability","details":"The updated packages fix a security vulnerability:\n\nA vulnerability in the Data-Loss-Prevention (DLP) module in Clam AntiVirus\n(ClamAV) Software versions 0.102.1 and 0.102.0 could allow an\nunauthenticated, remote attacker to cause a denial of service condition on\nan affected device. The vulnerability is due to an out-of-bounds read\naffecting users that have enabled the optional DLP feature. An attacker\ncould exploit this vulnerability by sending a crafted email file to an\naffected device. An exploit could allow the attacker to cause the ClamAV\nscanning process crash, resulting in a denial of service condition.\n(CVE-2020-3123)\n","modified":"2026-04-16T04:43:30.361223449Z","published":"2020-02-26T10:21:01Z","upstream":["CVE-2020-3123"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2020-0105.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=26221"},{"type":"WEB","url":"https://usn.ubuntu.com/4280-1/"},{"type":"WEB","url":"https://blog.clamav.net/2020/02/clamav-01022-security-patch-released.html"}],"affected":[{"package":{"name":"clamav","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/clamav?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.102.2-1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2020-0105.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}