Description
A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to an integer underflow in a bounds check that allows for a heap buffer overflow read. An attacker could exploit this vulnerability by submitting a crafted file containing OLE2 content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process, resulting in a DoS condition on the affected software.
For a description of this vulnerability, see the .
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 debian 13 | | | 1.4.2+dfsg-1 |
 debian 11 | | =0.103.10+dfsg-0+deb11u1 || =0.103.2+dfsg-2 || =0.103.3+dfsg-0+deb11u1 || =0.103.3+dfsg-1 || =0.103.4+dfsg-0+deb11u1 || =0.103.4+dfsg-1 || =0.103.5+dfsg-0+deb11u1 || =0.103.5+dfsg-1 || =0.103.6+dfsg-0+deb11u1 || =0.103.6+dfsg-1 || =0.103.7+dfsg-0+deb11u1 || =0.103.7+dfsg-1 || =0.103.8+dfsg-0+deb11u1 || =0.103.9+dfsg-0+deb11u1 || =1.0.0+dfsg-1 || =1.0.0+dfsg-2 || =1.0.0+dfsg-3 || =1.0.0+dfsg-4 || =1.0.0+dfsg-5 || =1.0.0+dfsg-6 || =1.0.1+dfsg-1 || =1.0.1+dfsg-2 || =1.0.2+dfsg-1 || =1.0.2+dfsg-1~deb12u1 || =1.0.3+dfsg-1 || =1.0.3+dfsg-1~deb12u1 || =1.0.3+dfsg-2 || =1.0.4+dfsg-1 || =1.0.5+dfsg-1 || =1.0.5+dfsg-1.1 || =1.0.5+dfsg-1~deb12u1 || =1.0.6+dfsg-1 || =1.0.7+dfsg-1~deb11u1 || =1.0.7+dfsg-1~deb11u2 || =1.0.7+dfsg-1~deb12u1 || >=0 <1.0.9+dfsg-1~deb11u1 | 1.0.9+dfsg-1~deb11u1 |
 debian 12 | | =1.0.1+dfsg-2 || =1.0.2+dfsg-1 || =1.0.2+dfsg-1~deb12u1 || =1.0.3+dfsg-1 || =1.0.3+dfsg-1~deb12u1 || =1.0.3+dfsg-2 || =1.0.4+dfsg-1 || =1.0.5+dfsg-1 || =1.0.5+dfsg-1.1 || =1.0.5+dfsg-1~deb12u1 || =1.0.6+dfsg-1 || =1.0.7+dfsg-1~deb11u1 || =1.0.7+dfsg-1~deb11u2 || =1.0.7+dfsg-1~deb12u1 || =1.0.9+dfsg-1~deb11u1 || >=0 <1.0.9+dfsg-1~deb12u1 | 1.0.9+dfsg-1~deb12u1 |
 debian 14 | | | 1.4.2+dfsg-1 |