FreshPorts - VuXML
This page displays vulnerability information about FreeBSD Ports.
The VUXML data was last processed by FreshPorts on 2025-07-20 04:36:57 UTC
List all Vulnerabilities, by package
List all Vulnerabilities, by date
k68
These are the vulnerabilities relating to the commit you have selected:
VuXML ID | Description |
3dcc0812-4da5-11f0-afcc-f02f7432cf97 | clamav -- ClamAV PDF Scanning Buffer Overflow Vulnerability
Cisco reports:
A vulnerability in the PDF scanning processes of ClamAV could allow
an unauthenticated, remote attacker to cause a buffer overflow
condition, cause a denial of service (DoS) condition, or execute
arbitrary code on an affected device.
This vulnerability exists because memory buffers are allocated
incorrectly when PDF files are processed. An attacker could exploit
this vulnerability by submitting a crafted PDF file to be scanned
by ClamAV on an affected device. A successful exploit could allow
the attacker to trigger a buffer overflow, likely resulting in the
termination of the ClamAV scanning process and a DoS condition on
the affected software. Although unproven, there is also a possibility
that an attacker could leverage the buffer overflow to execute
arbitrary code with the privileges of the ClamAV process.
Discovery 2025-06-18 Entry 2025-06-20 clamav
< 1.4.3,1
CVE-2025-20260
https://nvd.nist.gov/vuln/detail/CVE-2025-20260
|
6c6c1507-4da5-11f0-afcc-f02f7432cf97 | clamav -- ClamAV UDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Cisco reports:
A vulnerability in Universal Disk Format (UDF) processing of ClamAV
could allow an unauthenticated, remote attacker to cause a denial
of service (DoS) condition on an affected device.
This vulnerability is due to a memory overread during UDF file
scanning. An attacker could exploit this vulnerability by submitting
a crafted file containing UDF content to be scanned by ClamAV on
an affected device. A successful exploit could allow the attacker
to terminate the ClamAV scanning process, resulting in a DoS condition
on the affected software. For a description of this vulnerability,
see the .
Discovery 2025-06-18 Entry 2025-06-20 clamav
>= 1.2.0,1 lt 1.4.3,1
CVE-2025-20234
https://nvd.nist.gov/vuln/detail/CVE-2025-20234
|