DoS Vulnerability in ClamAV's Mach-O File Format Parser
CVE-2026-20347
7.5HIGH
What is CVE-2026-20347?
A flaw exists in ClamAV's Mach-O file format parser that may allow an unauthenticated remote attacker to exploit memory corruption vulnerabilities. This potential exploitation can lead to a Denial of Service condition, causing the ClamAV scanning process to unexpectedly terminate. The issue arises from improper boundary checks when scanning Mach-O files. Attackers can leverage this vulnerability by providing a specially crafted Mach-O file, which when processed by ClamAV, could lead to out-of-bounds buffer reads and subsequent application failure.
Affected Version(s)
Cisco Secure Endpoint 7.0.5
Cisco Secure Endpoint 6.2.19
Cisco Secure Endpoint 7.3.3