This vulnerability is due to a memory overread during UDF file scanning. An attacker could exploit this vulnerability by submitting a crafted file containing UDF content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process, resulting in a DoS condition on the affected software.
For a description of this vulnerability, see the .
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27685 | A vulnerability in Universal Disk Format (UDF) processing of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a memory overread during UDF file scanning. An attacker could exploit this vulnerability by submitting a crafted file containing UDF content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process, resulting in a DoS condition on the affected software. For a description of this vulnerability, see the . |
Ubuntu USN |
USN-7615-1 | ClamAV vulnerabilities |
Ubuntu USN |
USN-7615-2 | ClamAV vulnerabilities |
Mon, 11 Aug 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cisco
Cisco secure Endpoint Cisco secure Endpoint Private Cloud |
|
| CPEs | cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:linux:*:* cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:macos:*:* cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:windows:*:* cpe:2.3:a:cisco:secure_endpoint_private_cloud:*:*:*:*:*:*:*:* cpe:2.3:a:clamav:clamav:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Cisco
Cisco secure Endpoint Cisco secure Endpoint Private Cloud |
Wed, 18 Jun 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 18 Jun 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in Universal Disk Format (UDF) processing of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a memory overread during UDF file scanning. An attacker could exploit this vulnerability by submitting a crafted file containing UDF content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process, resulting in a DoS condition on the affected software. For a description of this vulnerability, see the . | |
| Title | ClamAV UDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2025-06-18T18:22:44.697Z
Reserved: 2024-10-10T19:15:13.237Z
Link: CVE-2025-20234
Updated: 2025-06-18T18:21:20.985Z
Status : Analyzed
Published: 2025-06-18T17:15:28.833
Modified: 2025-08-11T18:24:39.183
Link: CVE-2025-20234
No data.
OpenCVE Enrichment
Updated: 2025-06-20T13:55:53Z
EUVD
Ubuntu USN