Impact
ClamAV’s DMG file parser contains improper boundary checks that trigger an integer overflow on 32‑bit platforms, leading to memory corruption when a crafted DMG file is scanned. The flaw creates a classic buffer overflow (CWE‑120) combined with an integer overflow condition (CWE‑190) and can cause the ClamAV scanning process to terminate, resulting in a denial‑of‑service condition for the endpoint protection service.
Affected Systems
Cisco Secure Endpoint deployments that bundle ClamAV, especially on 32‑bit devices, are vulnerable. The CNA does not list specific ClamAV versions, so any instance of ClamAV included in Cisco Secure Endpoint should be considered potentially affected.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1 % suggests a low likelihood of exploitation. The vulnerability is not listed in CISA KEV, so no confirmed public exploitation exists. The likely attack vector is an unauthenticated attacker delivering a malicious DMG file to the ClamAV scanning process, either by placing it on the endpoint or via remote file upload mechanisms that trigger a scan. A successful exploit forces the scanning service to crash, potentially disrupting endpoint protection and broader network operations.
OpenCVE Enrichment
Ubuntu USN