{"id":"CVE-2022-20803","details":"A vulnerability in the OLE2 file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device.The vulnerability is due to incorrect use of the realloc function that may result in a double-free. An attacker could exploit this vulnerability by submitting a crafted OLE2 file to be scanned by ClamAV on the affected device. An exploit could allow the attacker to cause the ClamAV scanning process to crash, resulting in a denial of service condition.","modified":"2026-04-12T05:16:58.194549Z","published":"2023-02-17T18:15:11.740Z","references":[{"type":"ADVISORY","url":"https://blog.clamav.net/2022/05/clamav-01050-01043-01036-released.html"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202310-01"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cisco-talos/clamav","events":[{"introduced":"ba51bf8e644921a1592d2f3d280a2daa924acfd8"},{"fixed":"52edc04710856c5b2d29b29edf7a4eea2e6096c3"}],"database_specific":{"cpe":"cpe:2.3:a:clamav:clamav:*:*:*:*:*:*:*:*","source":"CPE_FIELD","extracted_events":[{"introduced":"0.104.0"},{"fixed":"0.104.3"}]}}],"versions":["clamav-0.104.0","clamav-0.104.1","clamav-0.104.2"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-20803.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}