FEDORA-EPEL-2018-aacf1b47d6

security update in Fedora EPEL 7 for clamav

Status: stable a year ago

Update to 0.99.4

0.99.4 addresses a few outstanding vulnerability bugs. It includes fixes for:

  • CVE-2012-6706
  • CVE-2017-6419
  • CVE-2017-11423
  • CVE-2018-1000085

There are also a few bug fixes that were not assigned CVE’s, but were important enough to address while we had the chance. One of these was the notorious file descriptor exhaustion bug that caused outages late last January.

In addition to the above, 0.99.4 fixes:

  • CVE-2018-0202: Two newly reported vulnerabilities in the PDF parsing code.

Comments 8

This update has been submitted for testing by orion.

This update has been pushed to testing.

OK

karma: +1

Seems to work.

karma: +1

Ran a couple of scans. Things worked fine.

karma: +1

This update has been submitted for batched by bodhi.

This update has been submitted for stable by bodhi.

This update has been pushed to stable.

Add Comment & Feedback

Please login to add feedback.

Content Type
RPM
Status
stable
Test Gating
Submitted by
Update Type
security
Update Severity
unspecified
Karma
+3
stable threshold: 3
unstable threshold: -3
Autopush (karma)
Enabled
Autopush (time)
Disabled
Dates
submitted a year ago
in testing a year ago
in stable a year ago

Related Bugs 2

00 #1549071 CVE-2018-1000085 clamav: Out-of-bounds heap read in XAR parser [fedora-all]
00 #1550747 clamav-0.99.4 is available

Automated Test Results

Test Cases

00 Test Case ClamAV