/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-hrr4-xgmj-8m9r

Published

Last updated

https://images.chainguard.dev/security/CGA-hrr4-xgmj-8m9r
Package

clamav-1.3

Repository

Chainguard

Latest Update
Fix not planned
Aliases
  • CVE-2025-20234
  • GHSA-xwph-f2wp-xxgp

Severity

7.5

High

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-20234

Updates

Status

Fix not planned

Impact

1.3 is EOL upstream (expected support periods are documented at https://docs.clamav.net/faq/faq-eol.html#version-support-matrix). As per https://blog.clamav.net/2025/06/clamav-143-and-109-security-patch.html users should upgrade to clamav-1.4 to receive the fix.

Status

Pending upstream fix

Impact

Upstream have introduced a fix in version 1.4.3 and 1.0.9. However, they are still working on introducing the fix into the main and other supported branches. It's expected that this CVE will be fixed once version 1.3.3 is tagged and released

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing