shield
Security update for clamav
SUSE-SLE-SERVER-12-SP2-2018-1561
This update for clamav to version 0.100.1 fixes the following issues: The following security vulnerabilities were addressed: - CVE-2018-0360: HWP integer overflow, infinite loop vulnerability (bsc#1101410) - CVE-2018-0361: PDF object length check, unreasonably long time to parse relatively small file (bsc#1101412) - CVE-2018-1000085: Fixed a out-of-bounds heap read in XAR parser (bsc#1082858) - CVE-2018-14679: Libmspack heap buffer over-read in CHM parser (bsc#1103040) - Buffer over-read in unRAR code due to missing max value checks in table initialization - PDF parser bugs The following other changes were made: - Disable YARA support for licensing reasons (bsc#1101654). - Add HTTPS support for clamsubmit - Fix for DNS resolution for users on IPv4-only machines where IPv6 is not available or is link-local only
-
Release DateAug 14 2018
-
ReferencesBugzilla: 1101654, 1101410, 1103040, 1101412, 1082858
CVEs: CVE-2018-14679, CVE-2018-0360, CVE-2018-0361, CVE-2018-1000085 -
Typesecurity
-
Severitymoderate
cloud_download Downloads
SUSE Linux Enterprise Server LTSS 12.2 ppc64le
-
Packages
SUSE Linux Enterprise Server LTSS 12.2 s390x
-
Packages
SUSE Linux Enterprise Server LTSS 12.2 x86_64
-
Packages