FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

clamav -- invalid pointer read that may cause a crash

Affected packages
clamav < 0.104.2,1
clamav-lts < 0.103.5,1

Details

VuXML ID 2a6106c6-73e5-11ec-8fa2-0800270512f4
Discovery 2022-01-12
Entry 2022-01-12

Laurent Delosieres reports:

Fix for invalid pointer read that may cause a crash. This issue affects 0.104.1, 0.103.4 and prior when ClamAV is compiled with libjson-c and the CL_SCAN_GENERAL_COLLECT_METADATA scan option (the clamscan --gen-json option) is enabled.

References

CVE Name CVE-2022-20698
URL https://blog.clamav.net/2022/01/clamav-01035-and-01042-security-patch.html