漏洞信息详情
Clam AntiVirus 缓冲区错误漏洞
漏洞简介
Clam AntiVirus是ClamAV团队的一款用于检测木马,病毒,恶意软件和其他恶意威胁的开源杀毒引擎。
Clam AntiVirus 0.102.1和0.102.0版本中的Data-Loss-Prevention (DLP)模块中存在缓冲区错误漏洞。远程攻击者可借助特制的文件利用该漏洞导致拒绝服务。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://blog.clamav.net/2020/02/clamav-01022-security-patch-released.html
参考网址
来源:UBUNTU
链接:https://usn.ubuntu.com/4280-1/
来源:UBUNTU
链接:https://usn.ubuntu.com/4280-2/
来源:GENTOO
链接:https://security.gentoo.org/glsa/202003-46
来源:CONFIRM
链接:https://blog.clamav.net/2020/02/clamav-01022-security-patch-released.html
来源:quickview.cloudapps.cisco.com
链接:https://quickview.cloudapps.cisco.com/quickview/bug/CSCvs59062
来源:blog.clamav.net
链接:https://blog.clamav.net/2020/02/clamav-01022-security-patch-released.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.0453/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4350/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/156831/Gentoo-Linux-Security-Advisory-202003-46.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0056/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4412/
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2020-3123
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/ClamAV-out-of-bounds-memory-reading-via-Credit-Card-DLP-31531
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/156402/Ubuntu-Security-Notice-USN-4280-1.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/156413/Ubuntu-Security-Notice-USN-4280-2.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/156227/Clam-AntiVirus-Toolkit-0.102.2.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.0565/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4540/
受影响实体
暂无
补丁
- Clam AntiVirus 缓冲区错误漏洞的修复措施<!--2020-2-5-->
还没有评论,来说两句吧...