CVE-2024-20380

A vulnerability in the HTML parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to an issue in the C to Rust foreign function interface. An attacker could exploit this vulnerability by submitting a crafted file containing HTML content to be scanned by ClamAV on an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Configurations

No configuration.

History

No history.

Information

Published : 2024-04-18 20:15

Updated : 2024-04-19 13:10


NVD link : CVE-2024-20380

Mitre link : CVE-2024-20380

CVE.ORG link : CVE-2024-20380


JSON object : View

Products Affected

No product.

CWE
CWE-475

Undefined Behavior for Input to API