VDB
CVE-2020-37167
CVE-2020-37167
REJECTED
CVSS 9.800000190734863 CRITICAL
ClamAV ClamBC bytecode interpreter contains a vulnerability in function name processing that allows attackers to manipulate bytecode function names. Attackers can exploit the weak input validation in function name encoding to potentially execute malicious bytecode or cause unexpected behavior in the ClamAV engine.
EPSS 0.17% · 6.6th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.17%
6.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:25.10 | clamav | 0, 1.4.2+dfsg-0ubuntu2, 1.4.2+dfsg-1ubuntu1 |
| Ubuntu:25.10 | libclamunrar | 1.3.1-1, 0, 1.3.1-1build1 |
| Ubuntu:Pro:14.04:LTS | clamav | *, 0.99.2+addedllvm-0ubuntu0.14.04.2, 0.99.3+addedllvm-0ubuntu0.14.04.1 |
| Ubuntu:24.04:LTS | clamav | 0, *, * |
| Ubuntu:16.04:LTS | libclamunrar | 0, *, 0.99-1ubuntu0.1 |
| Ubuntu:Pro:16.04:LTS | clamav | *, *, 0 |
| Ubuntu:24.04:LTS | libclamunrar | 1.3.1-0ubuntu0.24.04.1, 1.0.4-0ubuntu4, 0 |
| Ubuntu:18.04:LTS | libclamunrar | 0.99-4ubuntu1, 0, 0.101.2-1~ubuntu0.18.04.1 |
| Ubuntu:Pro:18.04:LTS | clamav | 0.100.1+dfsg-1ubuntu0.18.04.3, 0.99.4+addedllvm-0ubuntu1, 0.101.4+dfsg-0ubuntu0.18.04.1 |
| Ubuntu:22.04:LTS | libclamunrar | 1.3.1-0ubuntu0.22.04.1, 0.102.3-3, 0 |
| Ubuntu:Pro:20.04:LTS | clamav | 0.103.12+dfsg-0ubuntu0.20.04.1, 0.103.5+dfsg-1~20.04.1, 0.103.2+dfsg-0ubuntu0.20.04.2 |
| Ubuntu:22.04:LTS | clamav | 0.103.3+dfsg-1, 0.103.4+dfsg-1build1, 0.103.5+dfsg-1 |
| Ubuntu:Pro:20.04:LTS | libclamunrar | *, 0.101.2-1, 0 |
Timeline
- Feb 13, 2026 EPSS Score
- Feb 15, 2026 EPSS Score
- Feb 17, 2026 EPSS Score
- Feb 18, 2026 CVE Rejected
- Feb 18, 2026 CVE Updated
- Feb 19, 2026 EPSS Score
- Feb 21, 2026 EPSS Score
- Feb 23, 2026 EPSS Score
- Feb 25, 2026 EPSS Score
- Feb 27, 2026 EPSS Score
- Mar 1, 2026 EPSS Score
- Mar 3, 2026 EPSS Score
References
- https://ubuntu.com/security/CVE-2020-37167 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2020-37167 third-party-advisory
- https://www.exploit-db.com/exploits/47687 third-party-advisory
- https://www.vulncheck.com/advisories/clamav-clambc-clambc-executable-regular-expression third-party-advisory