ClamAV UDF File Parsing Out-of-Bounds Read Information Disclosure Vulnerability
A vulnerability in Universal Disk Format (UDF) processing of ClamAV could allow an unauthenticated, remote attacker to cause a denial service (DoS) condition on affected device.
This is due memory overread during file scanning. An exploit this by submitting crafted containing content be scanned device. A successful the terminate scanning process, resulting DoS software.
For description vulnerability, see blog.
Cisco has released software updates that address vulnerability. There are workarounds vulnerability.
This advisory available at following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-udf-hmwd9nDy
<br/>Security Impact Rating: Medium
<br/>CVE: CVE-2025-20234
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-udf-hmwd9nDy CISCO