* CVE-2021-1252, bsc#1184532: Fix for Excel XLM parser infinite

loop. Affects 0.103.0 and 0.103.1 only.
  * CVE-2021-1404, bsc#1184533: Fix for PDF parser buffer over-read;
    possible crash. Affects 0.103.0 and 0.103.1 only.
  * CVE-2021-1405, bsc#1184534: Fix for mail parser
    NULL-dereference crash. Affects 0.103.1 and prior.
  * bsc#1181256: Fix errors when scanning files > 4G

OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=220
This commit is contained in:
Reinhard Max 2021-04-09 08:50:38 +00:00 committed by Git OBS Bridge
parent b6dec3dc1b
commit aea56be75c

View File

@ -2,14 +2,12 @@
Wed Apr 7 20:05:49 UTC 2021 - Arjen de Korte <suse+build@de-korte.org>
- Update to 0.103.2
* CVE-2021-1386: Fix for UnRAR DLL load privilege escalation.
Affects 0.103.1 and prior on Windows only.
* CVE-2021-1252: Fix for Excel XLM parser infinite loop. Affects
0.103.0 and 0.103.1 only.
* CVE-2021-1404: Fix for PDF parser buffer over-read; possible
crash. Affects 0.103.0 and 0.103.1 only.
* CVE-2021-1405: Fix for mail parser NULL-dereference crash.
Affects 0.103.1 and prior.
* CVE-2021-1252, bsc#1184532: Fix for Excel XLM parser infinite
loop. Affects 0.103.0 and 0.103.1 only.
* CVE-2021-1404, bsc#1184533: Fix for PDF parser buffer over-read;
possible crash. Affects 0.103.0 and 0.103.1 only.
* CVE-2021-1405, bsc#1184534: Fix for mail parser
NULL-dereference crash. Affects 0.103.1 and prior.
* Fix possible memory leak in PNG parser.
* Fix ClamOnAcc scan on file-creation race condition so files are
scanned after their contents are written.
@ -24,6 +22,7 @@ Wed Apr 7 20:05:49 UTC 2021 - Arjen de Korte <suse+build@de-korte.org>
FreshClam user will have to take actions to get unblocked.
* Fix the FreshClam mirror-sync issue where a downloaded database is
"older than the version advertised."
* bsc#1181256: Fix errors when scanning files > 4G
- Update package signing key (from https://www.clamav.net/downloads)
% clamav.keyring