DoS Vulnerability in ClamAV Affects PESpin File Format Parsing
CVE-2026-20339
7.5HIGH
What is CVE-2026-20339?
A flaw in ClamAV's PESpin file format parser can lead to denial of service by allowing an unauthenticated remote attacker to exploit improper boundary checks. This can cause memory corruption and potential termination of the scanning process. By sending a specially crafted PESpin file for scanning, an attacker could trigger an integer overflow, compromising the functionality of ClamAV and affecting the software's operational reliability.
Affected Version(s)
Cisco Secure Endpoint 7.0.5
Cisco Secure Endpoint 6.2.19
Cisco Secure Endpoint 7.3.3