stable

clamav-0.98.7-1.el5

FEDORA-EPEL-2015-6081 created by robert 10 years ago for Fedora EPEL 5

ClamAV 0.98.7

This release contains new scanning features and bug fixes.

  • Improvements to PDF processing: decryption, escape sequence handling, and file property collection.
  • Scanning/analysis of additional Microsoft Office 2003 XML format.
  • Fix infinite loop condition on crafted y0da cryptor file. Identified and patch suggested by Sebastian Andrzej Siewior. CVE-2015-2221.
  • Fix crash on crafted petite packed file. Reported and patch supplied by Sebastian Andrzej Siewior. CVE-2015-2222.
  • Fix false negatives on files within iso9660 containers. This issue was reported by Minzhuan Gong.
  • Fix a couple crashes on crafted upack packed file. Identified and patches supplied by Sebastian Andrzej Siewior.
  • Fix a crash during algorithmic detection on crafted PE file. Identified and patch supplied by Sebastian Andrzej Siewior.
  • Fix an infinite loop condition on a crafted "xz" archive file. This was reported by Dimitri Kirchner and Goulven Guiheux. CVE-2015-2668.
  • Fix compilation error after ./configure --disable-pthreads. Reported and fix suggested by John E. Krokes.
  • Apply upstream patch for possible heap overflow in Henry Spencer's regex library. CVE-2015-2305.
  • Fix crash in upx decoder with crafted file. Discovered and patch supplied by Sebastian Andrzej Siewior. CVE-2015-2170.
  • Fix segfault scanning certain HTML files. Reported with sample by Kai Risku.
  • Improve detections within xar/pkg files.

This update has been submitted for testing by robert.

10 years ago

This update is currently being pushed to the Fedora EPEL 5 testing updates repository.

10 years ago

This update has been pushed to testing

10 years ago
User Icon gnat commented & provided feedback 10 years ago
karma

works on a couple of EL6 servers

This update has reached the stable karma threshold and will be pushed to the stable updates repository

10 years ago
User Icon gnat commented & provided feedback 10 years ago
karma

I meant EL5

User Icon neufeind provided feedback 10 years ago
karma

This update is currently being pushed to the Fedora EPEL 5 stable updates repository.

10 years ago

This update has been pushed to stable

10 years ago

Please log in to add feedback.

Metadata
Type
security
Karma
2
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
disabled
Stable by Time
disabled
Dates
submitted
10 years ago
in testing
10 years ago
in stable
10 years ago
modified
10 years ago
BZ#1217014 clamav-0.98.7 is available
0
0
BZ#1217206 CVE-2015-2221: clamav Infinite loop condition on crafted y0da cryptor file
0
0
BZ#1217207 CVE-2015-2222 clamav: crash on crafted petite packed file
0
0
BZ#1217208 CVE-2015-2668 clamav: Infinite loop condition on a crafted "xz" archive file
0
0
BZ#1217209 CVE-2015-2170: clamav: Crash in upx decoder with crafted file
0
0
BZ#1217514 clamav: multiple issues fixed in 0.98.7 [epel-all]
0
0

Automated Test Results

Test Cases

0 0 Test Case ClamAV