CVE-2026-20337 Details
Description
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bounds write condition. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
A denial-of-service vulnerability has been identified in ClamAV's zip archive parser. This issue allows an unauthenticated, remote attacker to cause a DoS condition on the affected device. The vulnerability arises from improper boundary checks for content in zip files during scanning, potentially leading to an out-of-bounds write condition. Exploitation involves submitting a crafted zip file for scanning, which can cause the ClamAV scanning process to terminate prematurely, disrupting normal operations.
Cisco has released software updates to address this vulnerability. For Cisco Secure Endpoint Private Cloud, the fixed software is available in releases 4.2.8 and later. Instructions for updating Cisco Secure Endpoint Connector clients are available through the Cisco Secure Endpoint portal.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-WuuvVd26 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 7, 2026 | CVE Modified | CISA-ADP |
| Aug 7, 2026 | New CVE Received | [email protected] |