CVE-2019-12625 PUBLISHED

ClamAV versions prior to 0.101.3 are susceptible to a zip bomb vulnerability where an unauthenticated attacker can cause a denial of service condition by sending crafted messages to an affected system.

EPSS 1.79% · 82.6th percentile

Risk Scores

EPSS Score
1.79%
82.6th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSclamav0, 0.100.3+dfsg-0ubuntu0.18.04.1, 0.100.2+dfsg-1ubuntu0.18.04.1
Ubuntu:16.04:LTSclamav0.99.2+dfsg-0ubuntu0.16.04.3, 0, 0.98.7+dfsg-0ubuntu4
Ubuntu:Pro:14.04:LTSclamav0.98.7+dfsg-0ubuntu0.14.04.1, 0.98.6+dfsg-0ubuntu0.14.04.1, 0.98.5+addedllvm-0ubuntu0.14.04.1

Timeline

References

Open in Interactive Console →