安全ID : QSA-25-04

Vulnerability in ClamAV Discovered by OSS-Fuzz


  • 发布日期 : January 28, 2025

  • 通用漏洞披露 : CVE-2025-20128

  • 受影响产品: None

严重程度

状态

未受影响


Summary

A security vulnerability has been identified in ClamAV, stemming from a potential buffer overflow read issue in the OLE2 file parser, which could result in a denial-of-service (DoS) condition.

After thorough investigation, we have determined that ClamAV for QTS and QuTS hero is not affected by this vulnerability.

Recommendation

We recommend regularly updating your system to the latest version to benefit from vulnerability fixes. You can check the product support status to see the latest updates available to your NAS model.

Reference

  

修订历史: V1.0 (January 28, 2025) - Published

选择规格

      显示更多 隐藏更多
      open menu
      back to top