CVE-2020-37167 PUBLISHED

ClamAV ClamBC <= 0.102.0 - 'ClamBC' Executable Regular Expression Error

Assigner: VulnCheck
Reserved: 06.02.2026 Published: 12.02.2026 Updated: 12.02.2026

ClamAV ClamBC bytecode interpreter contains a vulnerability in function name processing that allows attackers to manipulate bytecode function names. Attackers can exploit the weak input validation in function name encoding to potentially execute malicious bytecode or cause unexpected behavior in the ClamAV engine.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.6

Product Status

Vendor ClamAV
Product ClamBC
Versions
  • Version <= 0.102.0 is affected

References

Problem Types

  • Improper Control of Generation of Code ('Code Injection') CWE