{"id":"USN-6636-1","summary":"clamav vulnerabilities","details":"It was discovered that ClamAV incorrectly handled parsing certain OLE2\nfiles. A remote attacker could possibly use this issue to cause ClamAV to\ncrash, resulting in a denial of service. (CVE-2024-20290)\n\nAmit Schendel discovered that the ClamAV ClamD service incorrectly handled\nthe VirusEvent feature. An attacker able to connect to ClamD could possibly\nuse this issue to execute arbitrary code. (CVE-2024-20328)\n","modified":"2026-02-04T02:17:07.971953Z","published":"2024-02-14T16:11:25.366081Z","related":["CVE-2024-20290","CVE-2024-20328","UBUNTU-CVE-2024-20290","UBUNTU-CVE-2024-20328"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-6636-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-20290"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-20328"}],"affected":[{"package":{"name":"clamav","ecosystem":"Ubuntu:23.10","purl":"pkg:deb/ubuntu/clamav@1.0.5+dfsg-0ubuntu0.23.10.1?arch=source&distro=mantic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.5+dfsg-0ubuntu0.23.10.1"}]}],"versions":["0.103.8+dfsg-0ubuntu1","0.103.8+dfsg-0ubuntu2","1.0.2+dfsg-1ubuntu1","1.0.4+dfsg-0ubuntu0.23.10.1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"clamav","binary_version":"1.0.5+dfsg-0ubuntu0.23.10.1"},{"binary_name":"clamav-base","binary_version":"1.0.5+dfsg-0ubuntu0.23.10.1"},{"binary_name":"clamav-daemon","binary_version":"1.0.5+dfsg-0ubuntu0.23.10.1"},{"binary_name":"clamav-daemon-dbgsym","binary_version":"1.0.5+dfsg-0ubuntu0.23.10.1"},{"binary_name":"clamav-dbgsym","binary_version":"1.0.5+dfsg-0ubuntu0.23.10.1"},{"binary_name":"clamav-docs","binary_version":"1.0.5+dfsg-0ubuntu0.23.10.1"},{"binary_name":"clamav-freshclam","binary_version":"1.0.5+dfsg-0ubuntu0.23.10.1"},{"binary_name":"clamav-freshclam-dbgsym","binary_version":"1.0.5+dfsg-0ubuntu0.23.10.1"},{"binary_name":"clamav-milter","binary_version":"1.0.5+dfsg-0ubuntu0.23.10.1"},{"binary_name":"clamav-milter-dbgsym","binary_version":"1.0.5+dfsg-0ubuntu0.23.10.1"},{"binary_name":"clamav-testfiles","binary_version":"1.0.5+dfsg-0ubuntu0.23.10.1"},{"binary_name":"clamdscan","binary_version":"1.0.5+dfsg-0ubuntu0.23.10.1"},{"binary_name":"clamdscan-dbgsym","binary_version":"1.0.5+dfsg-0ubuntu0.23.10.1"},{"binary_name":"libclamav-dev","binary_version":"1.0.5+dfsg-0ubuntu0.23.10.1"},{"binary_version":"1.0.5+dfsg-0ubuntu0.23.10.1","binary_name":"libclamav11"},{"binary_name":"libclamav11-dbgsym","binary_version":"1.0.5+dfsg-0ubuntu0.23.10.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6636-1.json"}}],"schema_version":"1.7.3"}