Cisco has released new versions of ClamAV, the free antivirus package, to address vulnerabilities that could potentially allow attackers to execute code. The updates, ClamAV 1.4.6 and 1.5.4, aim to enhance security by patching various issues.
The vulnerabilities addressed in these releases include:
- CVE-2026-20337 – out-of-bounds write when processing specially formatted ZIP archive headers.
- CVE-2026-20345 – write and read buffer overflow when processing incorrect GPT partition names.
- CVE-2026-20339 – integer overflow in the PESpin unpacker, leading to an out-of-bounds write when parsing a PE file.
- CVE-2026-20338 – access to memory after it is freed in the ZIP archive handler.
- CVE-2026-20346 – integer overflow in the PDF parser.
- CVE-2026-20347 – integer overflow in the Mach-O executable file parser.
- CVE-2026-20348 – exhaustion of available memory when parsing specially designed files in the XAR format.
- CVE-2025-8088 – extraction of files to an area outside the root of the temporary directory when processing specially designed RAR archives on the Windows platform.
/Reports, release notes, official announcements.