CVE-2013-2020

Description

Integer underflow in the cli_scanpe function in pe.c in ClamAV before 0.97.8 allows remote attackers to cause a denial of service (crash) via a skewed offset larger than the size of the PE section in a UPX packed executable, which triggers an out-of-bounds read.

Risk Information

Base Score
6.2
MODERATE
Vector
AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
7.722

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Clamav 0.90.2_p0Windows
Multiple Vulnerabilities are affected in Clamav 0.91.2Windows
Multiple Vulnerabilities are affected in Clamav 0.9Windows
Multiple Vulnerabilities are affected in Clamav 0.90Windows
Multiple Vulnerabilities are affected in Clamav 0.90.1Windows
Multiple Vulnerabilities are affected in Clamav 0.90.1_p0Windows
Multiple Vulnerabilities are affected in Clamav 0.90.2Windows
Multiple Vulnerabilities are affected in Clamav 0.90.3Windows
Multiple Vulnerabilities are affected in Clamav 0.90.3_p0Windows
Multiple Vulnerabilities are affected in Clamav 0.90.3_p1Windows
Multiple Vulnerabilities are affected in Clamav 0.91Windows
Multiple Vulnerabilities are affected in Clamav 0.91.1Windows
Multiple Vulnerabilities are affected in Clamav 0.91.2_p0Windows
Multiple Vulnerabilities are affected in Clamav 0.92Windows
Multiple Vulnerabilities are affected in Clamav 0.92_p0Windows
Multiple Vulnerabilities are affected in Clamav 0.93.3Windows
Multiple Vulnerabilities are affected in Clamav 0.93.1Windows
Multiple Vulnerabilities are affected in Clamav 0.94.1Windows
Multiple Vulnerabilities are affected in Clamav 0.94Windows
Multiple Vulnerabilities are affected in Clamav 0.94.2Windows
Multiple Vulnerabilities are affected in Clamav 0.92.1Windows
Multiple Vulnerabilities are affected in Clamav 0.93Windows
Multiple Vulnerabilities are affected in Clamav 0.93.2Windows
Multiple Vulnerabilities are affected in Clamav 0.95Windows
Multiple Vulnerabilities are affected in Clamav 0.95.1Windows
Multiple Vulnerabilities are affected in Clamav 0.95.2Windows
Multiple Vulnerabilities are affected in Clamav 0.95.3Windows
Multiple Vulnerabilities are affected in Clamav 0.96Windows
Multiple Vulnerabilities are affected in Clamav 0.96.1Windows
Multiple Vulnerabilities are affected in Clamav 0.96.2Windows
Multiple Vulnerabilities are affected in Clamav 0.96.3Windows
Multiple Vulnerabilities are affected in Clamav 0.96.4Windows
Vulnerabilities CVE-2011-1003,CVE-2011-2721,CVE-2011-3627,CVE-2013-2020 are affected in Clamav 0.96.5Windows
Vulnerabilities CVE-2011-2721,CVE-2011-3627,CVE-2013-2020 are affected in Clamav 0.97Windows
Vulnerabilities CVE-2011-2721,CVE-2011-3627,CVE-2013-2020,CVE-2013-2021 are affected in Clamav 0.97.1Windows
Vulnerabilities CVE-2011-3627,CVE-2013-2020,CVE-2013-2021 are affected in Clamav 0.97.2Windows
Vulnerabilities CVE-2013-2020,CVE-2013-2021 are affected in Clamav 0.97.3Windows
Vulnerabilities CVE-2013-2020,CVE-2013-2021 are affected in Clamav 0.97.4Windows
Vulnerabilities CVE-2013-2020,CVE-2013-2021 are affected in Clamav 0.97.5Windows
Vulnerabilities CVE-2013-2020,CVE-2013-2021 are affected in Clamav 0.97.7Windows
Multiple vulnerabilities are fixed in OS X Mountain Lion Update v10.8.5 (Combo)Mac
Multiple vulnerabilities are fixed in OS X Mountain Lion Update v10.8.5Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-341177ClamAV (0.103.12)
PATCH-600057OS X Mountain Lion Update v10.8.5 (Combo)
PATCH-600058OS X Mountain Lion Update v10.8.5

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234