ClamAV versions prior to 0.101.3 are susceptible to a zip bomb vulnerability where an unauthenticated attacker can cause a denial of service condition by sending crafted messages to an affected system.
References
Configurations
History
No history.
Information
Published : 2019-11-05 19:15
Updated : 2019-12-01 01:15
NVD link : CVE-2019-12625
Mitre link : CVE-2019-12625
JSON object : View
Products Affected
clamav
- clamav
CWE
CWE-404
Improper Resource Shutdown or Release