stable

clamav-0.98.7-1.fc21

FEDORA-2015-7334 created by robert 10 years ago for Fedora 21

ClamAV 0.98.7

This release contains new scanning features and bug fixes.

  • Improvements to PDF processing: decryption, escape sequence handling, and file property collection.
  • Scanning/analysis of additional Microsoft Office 2003 XML format.
  • Fix infinite loop condition on crafted y0da cryptor file. Identified and patch suggested by Sebastian Andrzej Siewior. CVE-2015-2221.
  • Fix crash on crafted petite packed file. Reported and patch supplied by Sebastian Andrzej Siewior. CVE-2015-2222.
  • Fix false negatives on files within iso9660 containers. This issue was reported by Minzhuan Gong.
  • Fix a couple crashes on crafted upack packed file. Identified and patches supplied by Sebastian Andrzej Siewior.
  • Fix a crash during algorithmic detection on crafted PE file. Identified and patch supplied by Sebastian Andrzej Siewior.
  • Fix an infinite loop condition on a crafted "xz" archive file. This was reported by Dimitri Kirchner and Goulven Guiheux. CVE-2015-2668.
  • Fix compilation error after ./configure --disable-pthreads. Reported and fix suggested by John E. Krokes.
  • Apply upstream patch for possible heap overflow in Henry Spencer's regex library. CVE-2015-2305.
  • Fix crash in upx decoder with crafted file. Discovered and patch supplied by Sebastian Andrzej Siewior. CVE-2015-2170.
  • Fix segfault scanning certain HTML files. Reported with sample by Kai Risku.
  • Improve detections within xar/pkg files.

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2015-7334

This update has been submitted for testing by robert.

10 years ago

Taskotron: depcheck test PASSED on i386. Result log: https://taskotron.fedoraproject.org/taskmaster//builders/x86_64/builds/63766/steps/runtask/logs/stdio (results are informative only)

Taskotron: depcheck test PASSED on x86_64. Result log: https://taskotron.fedoraproject.org/taskmaster//builders/x86_64/builds/63766/steps/runtask/logs/stdio (results are informative only)

This update is currently being pushed to the Fedora 21 testing updates repository.

10 years ago
User Icon philipp commented & provided feedback 10 years ago
karma

Running on F21 in a production environment.

This update has been pushed to testing

10 years ago
User Icon neufeind provided feedback 10 years ago
karma

This update has reached the stable karma threshold and will be pushed to the stable updates repository

10 years ago

Taskotron: upgradepath test FAILED on noarch. Result log: https://taskotron.fedoraproject.org/taskmaster//builders/x86_64/builds/64508/steps/runtask/logs/stdio (results are informative only)

Automatic push to stable based on karma has been disabled for this update due to failure of an AutoQA test. Update submitter, please check the AutoQA test result and see if there is a valid problem to be fixed here, and fix it if so. If the failure is a mistake on AutoQA's part, you can re-enable the automatic push feature for this update if you like, or push it stable manually once it reaches the requirements under the Updates Policy.

10 years ago

This update is currently being pushed to the Fedora 21 stable updates repository.

10 years ago

This update has been pushed to stable

10 years ago

Please log in to add feedback.

Metadata
Type
security
Karma
2
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
disabled
Stable by Time
disabled
Dates
submitted
10 years ago
in testing
10 years ago
in stable
10 years ago
BZ#1217014 clamav-0.98.7 is available
0
0
BZ#1217206 CVE-2015-2221: clamav Infinite loop condition on crafted y0da cryptor file
0
0
BZ#1217207 CVE-2015-2222 clamav: crash on crafted petite packed file
0
0
BZ#1217208 CVE-2015-2668 clamav: Infinite loop condition on a crafted "xz" archive file
0
0
BZ#1217209 CVE-2015-2170: clamav: Crash in upx decoder with crafted file
0
0

Automated Test Results

Test Cases

0 0 Test Case ClamAV