cve-2025-20234
Vulnerability from cvelistv5
Published
2025-06-18 16:20
Modified
2025-06-18 18:22
Severity ?
EPSS score ?
Summary
ClamAV UDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
References
Impacted products
▼ | Vendor | Product |
---|---|---|
Cisco | Cisco Secure Endpoint |
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-20234", "options": [ { "Exploitation": "none" }, { "Automatable": "yes" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "timestamp": "2025-06-18T18:20:31.170035Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-06-18T18:22:44.697Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "defaultStatus": "unknown", "product": "Cisco Secure Endpoint", "vendor": "Cisco", "versions": [ { "status": "affected", "version": "7.0.5" }, { "status": "affected", "version": "6.2.19" }, { "status": "affected", "version": "7.3.3" }, { "status": "affected", "version": "7.2.13" }, { "status": "affected", "version": "6.1.5" }, { "status": "affected", "version": "6.3.1" }, { "status": "affected", "version": "6.2.5" }, { "status": "affected", "version": "7.3.5" }, { "status": "affected", "version": "6.2.1" }, { "status": "affected", "version": "7.2.7" }, { "status": "affected", "version": "7.1.1" }, { "status": "affected", "version": "6.3.5" }, { "status": "affected", "version": "6.2.9" }, { "status": "affected", "version": "7.3.1" }, { "status": "affected", "version": "6.1.7" }, { "status": "affected", "version": "7.2.11" }, { "status": "affected", "version": "7.2.3" }, { "status": "affected", "version": "7.1.5" }, { "status": "affected", "version": "6.3.3" }, { "status": "affected", "version": "7.3.9" }, { "status": "affected", "version": "6.2.3" }, { "status": "affected", "version": "6.1.9" }, { "status": "affected", "version": "6.0.9" }, { "status": "affected", "version": "7.2.5" }, { "status": "affected", "version": "6.0.7" }, { "status": "affected", "version": "6.3.7" }, { "status": "affected", "version": "1.12.3" }, { "status": "affected", "version": "1.8.0" }, { "status": "affected", "version": "1.11.1" }, { "status": "affected", "version": "1.12.4" }, { "status": "affected", "version": "1.10.0" }, { "status": "affected", "version": "1.12.0" }, { "status": "affected", "version": "1.8.1" }, { "status": "affected", "version": "1.10.1" }, { "status": "affected", "version": "1.12.1" }, { "status": "affected", "version": "1.12.6" }, { "status": "affected", "version": "1.14.0" }, { "status": "affected", "version": "1.10.2" }, { "status": "affected", "version": "1.12.7" }, { "status": "affected", "version": "1.12.2" }, { "status": "affected", "version": "1.6.0" }, { "status": "affected", "version": "1.9.0" }, { "status": "affected", "version": "1.11.0" }, { "status": "affected", "version": "1.7.0" }, { "status": "affected", "version": "1.13.0" }, { "status": "affected", "version": "1.8.4" }, { "status": "affected", "version": "1.13.1" }, { "status": "affected", "version": "1.9.1" }, { "status": "affected", "version": "1.12.5" }, { "status": "affected", "version": "1.13.2" }, { "status": "affected", "version": "8.1.7.21512" }, { "status": "affected", "version": "8.1.7" }, { "status": "affected", "version": "8.1.5" }, { "status": "affected", "version": "8.1.3.21242" }, { "status": "affected", "version": "8.1.3" }, { "status": "affected", "version": "8.1.5.21322" }, { "status": "affected", "version": "8.1.7.21417" }, { "status": "affected", "version": "1.14.1" }, { "status": "affected", "version": "1.15.2" }, { "status": "affected", "version": "1.15.3" }, { "status": "affected", "version": "1.15.4" }, { "status": "affected", "version": "1.15.6" }, { "status": "affected", "version": "1.16.0" }, { "status": "affected", "version": "1.16.1" }, { "status": "affected", "version": "1.16.2" }, { "status": "affected", "version": "1.16.3" }, { "status": "affected", "version": "1.18.1" }, { "status": "affected", "version": "1.21.0" }, { "status": "affected", "version": "1.21.2" }, { "status": "affected", "version": "1.22.4" }, { "status": "affected", "version": "1.24.1" }, { "status": "affected", "version": "1.24.2" }, { "status": "affected", "version": "1.24.4" }, { "status": "affected", "version": "1.17.0" } ] } ], "descriptions": [ { "lang": "en", "value": "A vulnerability in Universal Disk Format (UDF) processing of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.\r\n\r\nThis vulnerability is due to a memory overread during UDF file scanning. An attacker could exploit this vulnerability by submitting a crafted file containing UDF content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process, resulting in a DoS condition on the affected software.\r\nFor a description of this vulnerability, see the ." } ], "exploits": [ { "lang": "en", "value": "The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory." } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 5.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" }, "format": "cvssV3_1" } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-125", "description": "Out-of-bounds Read", "lang": "en", "type": "cwe" } ] } ], "providerMetadata": { "dateUpdated": "2025-06-18T16:20:01.175Z", "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633", "shortName": "cisco" }, "references": [ { "name": "cisco-sa-clamav-udf-hmwd9nDy", "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-udf-hmwd9nDy" }, { "name": "ClamAV blog", "url": "https://blog.clamav.net/2025/06/clamav-143-and-109-security-patch.html" } ], "source": { "advisory": "cisco-sa-clamav-udf-hmwd9nDy", "defects": [ "CSCwo45640" ], "discovery": "EXTERNAL" }, "title": "ClamAV UDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability" } }, "cveMetadata": { "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633", "assignerShortName": "cisco", "cveId": "CVE-2025-20234", "datePublished": "2025-06-18T16:20:01.175Z", "dateReserved": "2024-10-10T19:15:13.237Z", "dateUpdated": "2025-06-18T18:22:44.697Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1", "meta": { "nvd": "{\"cve\":{\"id\":\"CVE-2025-20234\",\"sourceIdentifier\":\"psirt@cisco.com\",\"published\":\"2025-06-18T17:15:28.833\",\"lastModified\":\"2025-06-23T20:16:59.783\",\"vulnStatus\":\"Awaiting Analysis\",\"cveTags\":[],\"descriptions\":[{\"lang\":\"en\",\"value\":\"A vulnerability in Universal Disk Format (UDF) processing of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.\\r\\n\\r\\nThis vulnerability is due to a memory overread during UDF file scanning. An attacker could exploit this vulnerability by submitting a crafted file containing UDF content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process, resulting in a DoS condition on the affected software.\\r\\nFor a description of this vulnerability, see the .\"},{\"lang\":\"es\",\"value\":\"Una vulnerabilidad en el procesamiento de Universal Disk Format (UDF) de ClamAV podr\u00eda permitir que un atacante remoto no autenticado provoque una denegaci\u00f3n de servicio (DoS) en un dispositivo afectado. Esta vulnerabilidad se debe a una sobrelectura de memoria durante el an\u00e1lisis de archivos UDF. Un atacante podr\u00eda explotar esta vulnerabilidad enviando un archivo manipulado con contenido UDF para que ClamAV lo analice en un dispositivo afectado. Una explotaci\u00f3n exitosa podr\u00eda permitir al atacante finalizar el proceso de an\u00e1lisis de ClamAV, lo que provocar\u00eda una denegaci\u00f3n de servicio (DoS) en el software afectado. Para obtener una descripci\u00f3n de esta vulnerabilidad, consulte [enlace faltante].\"}],\"metrics\":{\"cvssMetricV31\":[{\"source\":\"psirt@cisco.com\",\"type\":\"Primary\",\"cvssData\":{\"version\":\"3.1\",\"vectorString\":\"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L\",\"baseScore\":5.3,\"baseSeverity\":\"MEDIUM\",\"attackVector\":\"NETWORK\",\"attackComplexity\":\"LOW\",\"privilegesRequired\":\"NONE\",\"userInteraction\":\"NONE\",\"scope\":\"UNCHANGED\",\"confidentialityImpact\":\"NONE\",\"integrityImpact\":\"NONE\",\"availabilityImpact\":\"LOW\"},\"exploitabilityScore\":3.9,\"impactScore\":1.4}]},\"weaknesses\":[{\"source\":\"psirt@cisco.com\",\"type\":\"Primary\",\"description\":[{\"lang\":\"en\",\"value\":\"CWE-125\"}]}],\"references\":[{\"url\":\"https://blog.clamav.net/2025/06/clamav-143-and-109-security-patch.html\",\"source\":\"psirt@cisco.com\"},{\"url\":\"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-udf-hmwd9nDy\",\"source\":\"psirt@cisco.com\"}]}}" } }
Loading...
Loading...
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.