Ubuntu 16.04 ESM : ClamAV vulnerabilities (USN-5423-2)

high Nessus Plugin ID 161248

Synopsis

The remote Ubuntu host is missing one or more security updates.

Description

The remote Ubuntu 16.04 ESM host has packages installed that are affected by multiple vulnerabilities as referenced in the USN-5423-2 advisory.

USN-5423-1 fixed several vulnerabilities in ClamAV. This update provides the corresponding update for Ubuntu 14.04 ESM and 16.04 ESM.

Original advisory details:

Micha Dardas discovered that ClamAV incorrectly handled parsing CHM files.

A remote attacker could possibly use this issue to cause ClamAV to stop

responding, resulting in a denial of service.

(CVE-2022-20770)

Micha Dardas discovered that ClamAV incorrectly handled parsing TIFF

files. A remote attacker could possibly use this issue to cause ClamAV to

stop responding, resulting in a denial of service. (CVE-2022-20771)

Micha Dardas discovered that ClamAV incorrectly handled parsing HTML

files. A remote attacker could possibly use this issue to cause ClamAV to

consume resources, resulting in a denial of service. (CVE-2022-20785)

Micha Dardas discovered that ClamAV incorrectly handled loading the

signature database. A remote attacker could possibly use this issue to

cause ClamAV to crash, resulting in a denial of service, or possibly

execute arbitrary code. (CVE-2022-20792)

Alexander Patrakov and Antoine Gatineau discovered that ClamAV incorrectly

handled the scan verdict cache check. A remote attacker could possibly use

this issue to cause ClamAV to crash, resulting in a denial of service, or

possibly execute arbitrary code.(CVE-2022-20796)

Tenable has extracted the preceding description block directly from the Ubuntu security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://ubuntu.com/security/notices/USN-5423-2

Plugin Details

Severity: High

ID: 161248

File Name: ubuntu_USN-5423-2.nasl

Version: 1.10

Type: local

Agent: unix

Published: 5/17/2022

Updated: 8/28/2024

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2022-20785

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2022-20792

Vulnerability Information

CPE: p-cpe:/a:canonical:ubuntu_linux:clamdscan, p-cpe:/a:canonical:ubuntu_linux:libclamav-dev, p-cpe:/a:canonical:ubuntu_linux:clamav-freshclam, p-cpe:/a:canonical:ubuntu_linux:clamav-testfiles, p-cpe:/a:canonical:ubuntu_linux:clamav, p-cpe:/a:canonical:ubuntu_linux:clamav-milter, p-cpe:/a:canonical:ubuntu_linux:libclamav9, p-cpe:/a:canonical:ubuntu_linux:clamav-daemon, cpe:/o:canonical:ubuntu_linux:16.04:-:esm, p-cpe:/a:canonical:ubuntu_linux:clamav-base

Required KB Items: Host/cpu, Host/Debian/dpkg-l, Host/Ubuntu, Host/Ubuntu/release

Exploit Ease: No known exploits are available

Patch Publication Date: 5/17/2022

Vulnerability Publication Date: 5/4/2022

Reference Information

CVE: CVE-2022-20770, CVE-2022-20771, CVE-2022-20785, CVE-2022-20792, CVE-2022-20796

USN: 5423-2