USN-8788-1: ClamAV vulnerabilities
Cosa significa
ClamAV, un'utilità antivirus per Unix, presenta diverse vulnerabilità che permettono a un attaccante remoto di causare un denial of service. Le vulnerabilità interessano file ZIP, PESpin, GPT, PDF, Mach-O e XAR. La patch è disponibile per diverse versioni di ClamAV. L'attacco non è sfruttato attivamente in rete.
Perché conta
Le vulnerabilità di ClamAV possono portare a un denial of service, compromettendo la protezione antivirus e la continuità operativa. Le PMI italiane dipendono spesso da ClamAV per la sicurezza dei loro sistemi, rendendo questa vulnerabilità particolarmente rilevante.
Azioni consigliate
- Applica la patch disponibile per ClamAV (1.5.4+dfsg-0ubuntu0.26.04.1 e versioni successive).
- Verifica l'aggiornamento di tutti i sistemi che utilizzano ClamAV.
- Riduci l'accesso non autorizzato ai file di tipo ZIP, PESpin, GPT, PDF, Mach-O e XAR.
- Implementa un sistema di monitoraggio per rilevare crash improvvisi di ClamAV.
- Considera l'uso di Ubuntu Pro per ottenere una protezione aggiuntiva.
Sistemi e prodotti interessati
- ClamAV < 1.5.4+dfsg-0ubuntu0.26.04.1
- ClamAV < 1.5.4+dfsg-0ubuntu0.24.04.1
- ClamAV < 1.5.4+dfsg-0ubuntu0.22.04.1
Cosa cercare (rilevamento)
- Cerca log di crash improvvisi di ClamAV durante la scansione di file ZIP, PESpin, GPT, PDF, Mach-O o XAR.
- Monitora eventi di errore o segnalazioni di crash da parte di ClamAV.
- Verifica la presenza di file malevoli o anomali associati a questi formati.
- Controlla l'uso di risorse elevate da parte di ClamAV durante la scansione.
Estratto della fonte usato dal modello
Your submission was sent successfully! Close Thank you for contacting us. A member of our team will be in touch shortly. Close You have successfully unsubscribed! Close Thank you for signing up for our newsletter! In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team. Close Your preferences have been successfully updated. Close notification Please try again or file a bug report. Close USN-8788-1: ClamAV vulnerabilities Several security issues were fixed in ClamAV. clamav - Anti-virus utility for Unix It was discovered that ClamAV incorrectly handled certain zip archive files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. ( CVE-2026-20337 , CVE-2026-20338 ) It was discovered that ClamAV incorrectly handled certain PESpin files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. ( CVE-2026-20339 ) It was discovered that ClamAV incorrectly handled certain GPT files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. ( CVE-2026-20345 ) It was discovered that ClamAV incorrectly handled certain PDF files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of... It was discovered that ClamAV incorrectly handled certain zip archive files. A remote attacker could possibly use this issue to cause ClamAV to
Benefici operativi potenziali
- Riduzione della superficie esposta a vulnerabilità note.
- Miglioramento della resilienza contro attacchi di denial of service.
- Aumento della conformità alle normative di sicurezza.
Traduzione in elaborazione
Il contenuto ufficiale è disponibile nella lingua originale. La versione italiana verrà pubblicata al termine dei controlli automatici.
Testo acquisito dalla fonte
It was discovered that ClamAV incorrectly handled certain zip archive files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20337, CVE-2026-20338) It was discovered that ClamAV incorrectly handled certain PESpin files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20339) It was discovered that ClamAV incorrectly handled certain GPT files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20345) It was discovered that ClamAV incorrectly handled certain PDF files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20346) It was discovered that ClamAV incorrectly handled certain Mach-O files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20347) It was discovered that ClamAV incorrectly handled certain XAR files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20348)
- Fonte
- Ubuntu Security Notices
- Entità pubblicatrice
- Ubuntu Security
- Tipo entità
- vendor security
- Area
- Global
- Lingua originale
- en · traduzione in preparazione
- Pubblicazione
- 21/09/2026 14:05
- MITRE ATT&CK
- T1562
- CVE
- CVE-2026-20337, CVE-2026-20338, CVE-2026-20339, CVE-2026-20345, CVE-2026-20346, CVE-2026-20347, CVE-2026-20348
Prodotti e versioni interessati
Il collector verificherà NVD e gli advisory vendor ufficiali disponibili.