ClamAV versions prior to 0.101.3 are susceptible to a zip bomb vulnerability where an unauthenticated attacker can cause a denial of service condition by sending crafted messages to an affected system.
References
Configurations
Information
Published : 2019-11-05 11:15
Updated : 2019-11-30 17:15
NVD link : CVE-2019-12625
Mitre link : CVE-2019-12625
JSON object : View
CWE
CWE-404
Improper Resource Shutdown or Release
Products Affected
clamav
- clamav