security update in Fedora EPEL 6 for clamav

Status: stable 2 years ago

Update to 0.99.4

0.99.4 addresses a few outstanding vulnerability bugs. It includes fixes for:

  • CVE-2012-6706
  • CVE-2017-6419
  • CVE-2017-11423
  • CVE-2018-1000085

There are also a few bug fixes that were not assigned CVE’s, but were important enough to address while we had the chance. One of these was the notorious file descriptor exhaustion bug that caused outages late last January.

In addition to the above, 0.99.4 fixes:

  • CVE-2018-0202: Two newly reported vulnerabilities in the PDF parsing code.

Comments 8

This update has been submitted for testing by orion.

This update has been pushed to testing.

Have tested this on 2 systems.

karma: +1

Seems to work.

karma: +1

This update has been submitted for batched by bodhi.

This update has been submitted for stable by bodhi.

This update has been pushed to stable.

Add Comment & Feedback

Please login to add feedback.

Content Type
Test Gating
Submitted by
Update Type
Update Severity
stable threshold: 3
unstable threshold: -3
Autopush (karma)
Autopush (time)
submitted 2 years ago
in testing 2 years ago
in stable 2 years ago

Related Bugs 2

00 #1549071 CVE-2018-1000085 clamav: Out-of-bounds heap read in XAR parser [fedora-all]
00 #1550747 clamav-0.99.4 is available

Automated Test Results

Test Cases

00 Test Case ClamAV