Secure Endpoint and ClamAV

CVE-2024-20505: ClamAV Memory Handling DoS

A vulnerability in the PDF parsing module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2.x versions, 1.0.6 and prior versions, all 0.105.x versions, all 0.104.x versions, and 0.103.11 and all prior versions could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

Published

ExploitedNot in CISA KEV
Ransomware useNot reportedPer CISA
SeverityMEDIUMCVSS 3.1 4
EPSS0.56%Chance of exploitation in 30 days
Public exploitNot tracked
FixNot yet

Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.

Affected and fixed versions

Product / branchFixed in
ClamAV 1.4See the advisory
ClamAV 1.3See the advisory
ClamAV 1.0See the advisory
ClamAV 1.0See the advisory
ClamAV 1.0See the advisory
ClamAV 1.0See the advisory
ClamAV 1.0See the advisory
ClamAV 1.0See the advisory
ClamAV 1.0See the advisory
ClamAV 1.2See the advisory
ClamAV 0.105See the advisory
ClamAV 0.104See the advisory
ClamAV 0.103See the advisory
ClamAV 0.103See the advisory
ClamAV 0.103See the advisory
ClamAV 0.103See the advisory
ClamAV 0.103See the advisory
ClamAV 0.103See the advisory
ClamAV 0.103See the advisory
ClamAV 0.103See the advisory
ClamAV 0.103See the advisory
ClamAV 0.103See the advisory
ClamAV 0.103See the advisory
ClamAV 0.103See the advisory

Always confirm against the vendor advisory, which lists every fixed hotfix.

What it is

A vulnerability in the PDF parsing module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2.x versions, 1.0.6 and prior versions, all 0.105.x versions, all 0.104.x versions, and 0.103.11 and all prior versions could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

The vulnerability is due to an out of bounds read. An attacker could exploit this vulnerability by submitting a crafted PDF file to be scanned by ClamAV on an affected device. An exploit could allow the attacker to terminate the scanning process.

Sources

KEV status, EPSS score and vendor data refreshed automatically, last on 11 Oct 2026.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.