CVE-2025-20234

A vulnerability in Universal Disk Format (UDF) processing of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a memory overread during UDF file scanning. An attacker could exploit this vulnerability by submitting a crafted file containing UDF content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process, resulting in a DoS condition on the affected software. For a description of this vulnerability, see the .
Configurations

Configuration 1 (hide)

cpe:2.3:a:clamav:clamav:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:linux:*:*
cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:macos:*:*
cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:windows:*:*
cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:windows:*:*
cpe:2.3:a:cisco:secure_endpoint_private_cloud:*:*:*:*:*:*:*:*

History

11 Aug 2025, 18:24

Type Values Removed Values Added
First Time Clamav clamav
Cisco secure Endpoint
Cisco secure Endpoint Private Cloud
Clamav
Cisco
CPE cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:windows:*:*
cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:linux:*:*
cpe:2.3:a:clamav:clamav:*:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_endpoint_private_cloud:*:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:macos:*:*
References () https://blog.clamav.net/2025/06/clamav-143-and-109-security-patch.html - () https://blog.clamav.net/2025/06/clamav-143-and-109-security-patch.html - Vendor Advisory
References () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-udf-hmwd9nDy - () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-udf-hmwd9nDy - Third Party Advisory

23 Jun 2025, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-18 17:15

Updated : 2025-08-11 18:24


NVD link : CVE-2025-20234

Mitre link : CVE-2025-20234

CVE.ORG link : CVE-2025-20234


JSON object : View

Products Affected

clamav

  • clamav

cisco

  • secure_endpoint
  • secure_endpoint_private_cloud
CWE
CWE-125

Out-of-bounds Read