From aea56be75c3997a333c0d65e4745c33ea0106e157edf40b6d3b3d682d5675514 Mon Sep 17 00:00:00 2001 From: Reinhard Max Date: Fri, 9 Apr 2021 08:50:38 +0000 Subject: [PATCH] * CVE-2021-1252, bsc#1184532: Fix for Excel XLM parser infinite loop. Affects 0.103.0 and 0.103.1 only. * CVE-2021-1404, bsc#1184533: Fix for PDF parser buffer over-read; possible crash. Affects 0.103.0 and 0.103.1 only. * CVE-2021-1405, bsc#1184534: Fix for mail parser NULL-dereference crash. Affects 0.103.1 and prior. * bsc#1181256: Fix errors when scanning files > 4G OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=220 --- clamav.changes | 15 +++++++-------- 1 file changed, 7 insertions(+), 8 deletions(-) diff --git a/clamav.changes b/clamav.changes index 95d3269..3f856cf 100644 --- a/clamav.changes +++ b/clamav.changes @@ -2,14 +2,12 @@ Wed Apr 7 20:05:49 UTC 2021 - Arjen de Korte - Update to 0.103.2 - * CVE-2021-1386: Fix for UnRAR DLL load privilege escalation. - Affects 0.103.1 and prior on Windows only. - * CVE-2021-1252: Fix for Excel XLM parser infinite loop. Affects - 0.103.0 and 0.103.1 only. - * CVE-2021-1404: Fix for PDF parser buffer over-read; possible - crash. Affects 0.103.0 and 0.103.1 only. - * CVE-2021-1405: Fix for mail parser NULL-dereference crash. - Affects 0.103.1 and prior. + * CVE-2021-1252, bsc#1184532: Fix for Excel XLM parser infinite + loop. Affects 0.103.0 and 0.103.1 only. + * CVE-2021-1404, bsc#1184533: Fix for PDF parser buffer over-read; + possible crash. Affects 0.103.0 and 0.103.1 only. + * CVE-2021-1405, bsc#1184534: Fix for mail parser + NULL-dereference crash. Affects 0.103.1 and prior. * Fix possible memory leak in PNG parser. * Fix ClamOnAcc scan on file-creation race condition so files are scanned after their contents are written. @@ -24,6 +22,7 @@ Wed Apr 7 20:05:49 UTC 2021 - Arjen de Korte FreshClam user will have to take actions to get unblocked. * Fix the FreshClam mirror-sync issue where a downloaded database is "older than the version advertised." + * bsc#1181256: Fix errors when scanning files > 4G - Update package signing key (from https://www.clamav.net/downloads) % clamav.keyring