Update of the ClamAV antivirus package 1.4.3 and 1.0.9 with vulnerability fixes

Cisco has released new versions of the free ClamAV antivirus package 1.4.3 and 1.0.98, which fix vulnerabilities, one of which could allow an attacker to execute code when scanning specially crafted content.

  • CVE-2025-20260 — a bug in the code that parses PDF files, leading to data being written outside the allocated buffer. This issue occurs in configurations where the maximum file-size and scan-size settings are equal to or exceed 1024 MB and 1025 MB, respectively. The vulnerability has been exploitable since version 1.0.0 and may allow code execution with the privileges of the ClamAV process.
  • CVE-2025-20234 — a bug in the code that parses UDF files, leading to reading data from memory outside the allocated buffer. This issue may cause the process to crash or leak data from memory to a temporary file. The vulnerability is present starting from version 1.2.0.
  • Memory access after it has been freed in the xz archive unpacking module (CVE not assigned). The issue is caused by a bug in the lzma-sdk library built into ClamAV, which was fixed in the main project with the release of lzma-sdk 18.03 published in 2018 without mentioning any vulnerability fixes. This vulnerability is present in all versions of ClamAV starting from 0.99.4.

    Source: opennet.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster