Alpine: multiple clamav packages, multiple freshclam packages: security update to 1.3.2-r0

medium Tenable Self-Hosted Container Security Plugin ID 426145

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- A vulnerability in the PDF parsing module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior
versions, all 1.2.x versions, 1.0.6 and prior versions, all 0.105.x versions, all 0.104.x versions, and
0.103.11 and all prior versions could allow an unauthenticated, remote attacker to cause a denial of
service (DoS) condition on an affected device. The vulnerability is due to an out of bounds read. An
attacker could exploit this vulnerability by submitting a crafted PDF file to be scanned by ClamAV on an
affected device. An exploit could allow the attacker to terminate the scanning process. (CVE-2024-20505)

- A vulnerability in the ClamD service module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior
versions, all 1.2.x versions, 1.0.6 and prior versions, all 0.105.x versions, all 0.104.x versions, and
0.103.11 and all prior versions could allow an authenticated, local attacker to corrupt critical system
files. The vulnerability is due to allowing the ClamD process to write to its log file while privileged
without checking if the logfile has been replaced with a symbolic link. An attacker could exploit this
vulnerability if they replace the ClamD log file with a symlink to a critical system file and then find a
way to restart the ClamD process. An exploit could allow the attacker to corrupt a critical system file by
appending ClamD log messages after restart. (CVE-2024-20506)

See Also

https://security.alpinelinux.org/vuln/CVE-2024-20505

https://security.alpinelinux.org/vuln/CVE-2024-20506

Plugin Details

Severity: Medium

ID: 426145

Version: Revision 1.9

Type: Local

Published: 5/16/2025

Updated: 7/2/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3.5

Percentile: 51.63

CVSS v2

Risk Factor: Medium

Base Score: 5.2

Temporal Score: 3.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:P/A:C

CVSS Score Source: CVE-2024-20506

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 5.3

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 9/4/2024

Reference Information

CVE: CVE-2024-20505, CVE-2024-20506

IAVB: 2024-B-0134-S