Cisco has released new releases of its free ClamAV antivirus suite, ClamAV 1.4.6 and 1.5.4, which address vulnerabilities, some of which could lead to attacker code execution when scanning specially crafted content.
- CVE-2026-20337 - Out-of-bounds write vulnerability when processing specially crafted ZIP archive headers.
- CVE-2026-20345 – Buffer overflow on write and read when handling invalid GPT partition names.
- CVE-2026-20339 - An integer overflow in the PESpin unpacker leads to an out-of-bounds write when executing a PE file.
- CVE-2026-20338 - Access after free vulnerability in ZIP archive handler.
- CVE-2026-20346 - Integer overflow in PDF parser.
- CVE-2026-20347 - Integer overflow in the Mach-O executable parser.
- CVE-2026-20348 - Exhaustion of available memory when parsing specially crafted XAR files.
- CVE-2025-8088 - File extraction to an area outside the root of the temporary directory when processing specially crafted RAR archives on the platform Windows.
Source: opennet.ru
