Cisco has released new versions of the free antivirus package ClamAV 1.0.1, 0.105.3, and 0.103.8, which address a critical vulnerability (CVE-2023-20032) that could allow code execution while scanning files with specially crafted HFS+ disk images in ClamAV.
The vulnerability arises from inadequate buffer size checks, allowing data to be written outside the buffer's boundaries and enabling code execution with the privileges of the ClamAV process, such as when scanning files extracted from emails on a mail server. Updates for the packages across distributions can be tracked on the following pages: Debian, Ubuntu, Gentoo, RHEL, SUSE, Arch, FreeBSD, NetBSD.
The new releases also fix another vulnerability (CVE-2023-20052) that could lead to the leakage of content from any files accessible to the scanning process. serverThis vulnerability occurs when parsing specially crafted DMG files, caused by the parser allowing the injection of external XML elements linked in the DMG file being parsed.
Source: opennet.ru
