291 Commits

Author SHA256 Message Date
Ana Guerrero
0c3339881d Accepting request 1231926 from security
- fix factory submission (clam.tcl, clamscan.log) (forwarded request 1231922 from AndreasStieger)

OBS-URL: https://build.opensuse.org/request/show/1231926
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=127
2024-12-18 19:11:19 +00:00
Reinhard Max
33b181b0e5 - fix factory submission (clam.tcl, clamscan.log)
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=268
2024-12-18 16:14:20 +00:00
Reinhard Max
7c9dfc0617 - fix factory submission (clam.tcl)
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=267
2024-12-18 13:56:22 +00:00
Reinhard Max
adb646ae3c OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=266 2024-09-10 14:24:43 +00:00
Reinhard Max
652f75b4ea OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=265 2024-09-10 13:46:52 +00:00
Reinhard Max
4be77ca9be - New version 1.4.1:
* [CVE-2024-20506, bsc#1230162]: Changed the logging module to
    disable following symlinks on Linux and Unix systems so as to
    prevent an attacker with existing access to the 'clamd' or
    'freshclam' services from using a symlink to corrupt system
    files.
  * [CVE-2024-20505, bsc#1230161]: Fixed a possible out-of-bounds
    read bug in the PDF file parser that could cause a
    denial-of-service (DoS) condition.
  * https://blog.clamav.net/2024/09/clamav-141-132-107-and-010312-security.html
- New version 1.4.0:
  * Added support for extracting ALZ archives.
  * Added support for extracting LHA/LZH archives.
  * Added the ability to disable image fuzzy hashing, if needed.
    For context, image fuzzy hashing is a detection mechanism
    useful for identifying malware by matching images included with
    the malware or phishing email/document.
  * https://blog.clamav.net/2024/08/clamav-140-feature-release-and-clamav.html

OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=264
2024-09-10 13:35:10 +00:00
Reinhard Max
896f44d06a Accepting request 1198813 from home:adkorte:branches:security
- New version 1.3.2:
  * CVE-2024-20506: Changed the logging module to disable following
    symlinks on Linux and Unix systems so as to prevent an attacker
    with existing access to the 'clamd' or 'freshclam' services from
    using a symlink to corrupt system files.
  * CVE-2024-20505: Fixed a possible out-of-bounds read bug in the PDF
    file parser that could cause a denial-of-service condition.
  * Removed unused Python modules from freshclam tests including
    deprecated 'cgi' module that is expected to cause test failures in
    Python 3.13.
  * Fix unit test caused by expiring signing certificate.
  * Fixed a build issue on Windows with newer versions of Rust. Also
    upgraded GitHub Actions imports to fix CI failures.
  * Fixed an unaligned pointer dereference issue on select architectures.
  * Fixes to Jenkins CI pipeline.
- Remove upstreamed 1305.patch

OBS-URL: https://build.opensuse.org/request/show/1198813
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=263
2024-09-09 12:39:53 +00:00
Dominique Leuenberger
5dcb5fee0f Accepting request 1190182 from security
OBS-URL: https://build.opensuse.org/request/show/1190182
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=126
2024-07-29 19:52:52 +00:00
Reinhard Max
9f8b189366 Add upstream 1305.patch to fix tests (boo#1102840, https://github.com/Cisco-Talos/clamav/issues/1300)
Note: it uses git apply for the binary patch of test.exe

OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=261
2024-07-29 08:05:33 +00:00
Ana Guerrero
37c4b40e34 Accepting request 1184343 from security
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/1184343
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=125
2024-07-02 16:17:36 +00:00
Reinhard Max
d5c48bd5cc OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=259 2024-06-24 15:32:35 +00:00
Reinhard Max
8604eed583 OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=258 2024-06-21 11:01:38 +00:00
Reinhard Max
dec2994d4b OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=257 2024-06-21 07:20:21 +00:00
Reinhard Max
697f22b85f OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=256 2024-06-20 13:25:04 +00:00
Reinhard Max
6671c35595 fix build on Factory
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=255
2024-06-19 15:20:48 +00:00
Reinhard Max
a7e3babd61 - New Version: 1.3.1:
* CVE-2024-20380: Fixed a possible crash in the HTML file parser
    that could cause a denial-of-service (DoS) condition.
  * Updated select Rust dependencies to the latest versions.
  * Fixed a bug causing some text to be truncated when converting
    from UTF-16.
  * Fixed assorted complaints identified by Coverity static
    analysis.
  * Fixed a bug causing CVDs downloaded by the DatabaseCustomURL
    Freshclam config option to be pruned and then re-downloaded
    with every update.
  * Added the new 'valhalla' database name to the list of optional
    databases in preparation for future work.
- Drop clamav-disable-yara.patch as yara cannot be disabled anymore

OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=254
2024-04-22 15:34:13 +00:00
Reinhard Max
4c0d696200 OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=253 2024-04-04 15:07:42 +00:00
Reinhard Max
9f7e5bf9ea Accepting request 1161540 from home:rmax:branches:security
- New version: 1.3.0:
  * Added support for extracting and scanning attachments found in
    Microsoft OneNote section files. OneNote parsing will be
    enabled by default, but may be optionally disabled.
  * Added file type recognition for compiled Python (`.pyc`) files.
  * Improved support for decrypting PDFs with empty passwords.
  * Fixed a warning when scanning some HTML files.
  * ClamOnAcc: Fixed an infinite loop when a watched directory
    does not exist.
  * ClamOnAcc: Fixed an infinite loop when a file has been deleted
    before a scan.
- Use %patch -P N instead of deprecated %patchN.
- New version: 1.2.0:
  * Added support for extracting Universal Disk Format (UDF)
    partitions.
  * Added an option to customize the size of ClamAV's clean file
    cache.
  * Raised the MaxScanSize limit so the total amount of data
    scanned when scanning a file or archive may exceed 4 gigabytes.
  * Added ability for Freshclam to use a client certificate PEM
    file and a private key PEM file for authentication to a private
    mirror.
  * Fix an issue extracting files from ISO9660 partitions where the
    files are listed in the plain ISO tree and there also exists an
    empty Joliet tree.
  * PID and socket are now located under /run/clamav/clamd.pid and
    /run/clamav/clamd.sock .
  * bsc#1211594: Fixed an issue where ClamAV does not abort the
    signature load process after partially loading an invalid
    signature.

OBS-URL: https://build.opensuse.org/request/show/1161540
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=252
2024-03-25 18:13:50 +00:00
Ana Guerrero
d25fefd232 Accepting request 1151661 from security
OBS-URL: https://build.opensuse.org/request/show/1151661
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=124
2024-02-26 18:48:32 +00:00
Reinhard Max
393ffa0338 Accepting request 1151087 from home:dimstar:rpm4.20:c
Prepare for RPM 4.20

OBS-URL: https://build.opensuse.org/request/show/1151087
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=250
2024-02-26 13:52:49 +00:00
Ana Guerrero
6c8eaf7217 Accepting request 1122919 from security
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/1122919
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=123
2023-11-02 19:23:16 +00:00
Reinhard Max
9ebe900e55 Add bugzilla and CVE reference
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=248
2023-10-26 15:45:16 +00:00
Ana Guerrero
09d196dae1 Accepting request 1120590 from security
OBS-URL: https://build.opensuse.org/request/show/1120590
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=122
2023-10-26 15:15:20 +00:00
Reinhard Max
d4f9bd6fc9 Accepting request 1120366 from home:adkorte:branches:security
- Update to 0.103.11
  * Upgrade the bundled UnRAR library (libclamunrar) to version 6.2.12.
  * Windows: libjson-c 0.17 compatibility fix. with ssize_t type definition.
  * Windows: Update build system to use OpenSSL 3 and PThreads-Win32 v3.
- Update to 0.103.10
  * Upgrade the bundled UnRAR library (libclamunrar) to version 6.2.10.

OBS-URL: https://build.opensuse.org/request/show/1120366
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=246
2023-10-26 13:32:31 +00:00
Ana Guerrero
2ae20ef73b Accepting request 1105919 from security
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/1105919
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=121
2023-08-28 15:13:25 +00:00
Reinhard Max
f750401fdc OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=244 2023-08-18 14:03:24 +00:00
Reinhard Max
6bdefd2c39 OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=243 2023-08-18 14:00:53 +00:00
Reinhard Max
0c1991c29e - Renew clamav.keyring .
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=242
2023-08-18 13:19:37 +00:00
Reinhard Max
79bdf6ebb0 Accepting request 1104230 from home:adkorte:branches:security
- Update to 0.103.9
  * CVE-2023-20197: Fixed a possible denial of service vulnerability in
    the HFS+ file parser. This issue affects versions 1.1.0, 1.0.1 through
    1.0.0, 0.105.2 through 0.105.0, 0.104.4 through 0.104.0, and 0.103.8
    through 0.103.0. (boo#1214342)
  * Fixed compiler warnings that may turn into errors in Clang 16.

OBS-URL: https://build.opensuse.org/request/show/1104230
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=241
2023-08-16 18:49:44 +00:00
Dominique Leuenberger
229d0e65c5 Accepting request 1066149 from security
- Update to 0.103.8
  * CVE-2023-20032: Fixed a possible remote code execution vulnerability
    in the HFS+ file parser. Issue affects versions 1.0.0 and earlier,
    0.105.1 and earlier, and 0.103.7 and earlier. (bsc#1208363)
  * CVE-2023-20052: Fixed a possible remote information leak
    vulnerability in the DMG file parser. Issue affects versions 1.0.0
    and earlier, 0.105.1 and earlier, and 0.103.7 and earlier.
    (bsc#1208365)
  * Update vendored libmspack library to version 0.11alpha.
- Package huge .html documentation in a separate subpackage.

OBS-URL: https://build.opensuse.org/request/show/1066149
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=120
2023-02-16 15:57:09 +00:00
Reinhard Max
8dcf736f6a 0.105.1 and earlier, and 0.103.7 and earlier. (bsc#1208363)
(bsc#1208365)

OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=239
2023-02-16 10:21:28 +00:00
Reinhard Max
2efd340a5a Accepting request 1066029 from home:adkorte:branches:security
- Update to 0.103.8
  * CVE-2023-20032: Fixed a possible remote code execution vulnerability
    in the HFS+ file parser. Issue affects versions 1.0.0 and earlier,
    0.105.1 and earlier, and 0.103.7 and earlier.
  * CVE-2023-20052: Fixed a possible remote information leak
    vulnerability in the DMG file parser. Issue affects versions 1.0.0
    and earlier, 0.105.1 and earlier, and 0.103.7 and earlier.
  * Update vendored libmspack library to version 0.11alpha.
- Package huge .html documentation in a separate subpackage.

OBS-URL: https://build.opensuse.org/request/show/1066029
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=238
2023-02-16 09:53:43 +00:00
Dominique Leuenberger
412e335eb2 Accepting request 993801 from security
OBS-URL: https://build.opensuse.org/request/show/993801
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=119
2022-08-09 13:27:30 +00:00
Reinhard Max
35824f3ad3 Accepting request 993249 from home:ecsos
- Update to 0.103.7
  - Zip parser: tolerate 2-byte overlap in file entries
  - Fix bug with logical signature Intermediates feature
  - Update to UnRAR v6.1.7
  - Patch UnRAR: allow skipping files in solid archives
  - Patch UnRAR: limit dict winsize to 1GB

OBS-URL: https://build.opensuse.org/request/show/993249
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=236
2022-08-08 14:18:42 +00:00
Dominique Leuenberger
a5795499ce Accepting request 975373 from security
update clamav to 0.103.6

OBS-URL: https://build.opensuse.org/request/show/975373
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=118
2022-05-06 16:59:55 +00:00
Robert Frohl
17cc3145e0 created new boo# for missing CVE
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=234
2022-05-06 09:39:17 +00:00
Robert Frohl
42d69218c0 add missing boo#
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=233
2022-05-06 09:32:31 +00:00
Robert Frohl
a2ea93b424 Accepting request 975241 from home:adkorte:branches:security
- Update to 0.103.6
  * CVE-2022-20770: Fixed a possible infinite loop vulnerability in the CHM
    file parser. Issue affects versions 0.104.0 through 0.104.2 and LTS
    version 0.103.5 and prior versions.
  * CVE-2022-20796: Fixed a possible NULL-pointer dereference crash in the
    scan verdict cache check. Issue affects versions 0.103.4, 0.103.5,
    0.104.1, and 0.104.2.
  * CVE-2022-20771: Fixed a possible infinite loop vulnerability in the
    TIFF file parser. Issue affects versions 0.104.0 through 0.104.2 and
    LTS version 0.103.5 and prior versions. The issue only occurs if the
    "--alert-broken-media" ClamScan option is enabled. For ClamD, the
    affected option is "AlertBrokenMedia yes", and for libclamav it is the
    "CL_SCAN_HEURISTIC_BROKEN_MEDIA" scan option.
  * CVE-2022-20785: Fixed a possible memory leak in the HTML file parser /
    Javascript normalizer. Issue affects versions 0.104.0 through 0.104.2
    and LTS version 0.103.5 and prior versions.
  * CVE-2022-20792: Fixed a possible multi-byte heap buffer overflow write
    vulnerability in the signature database load module. The fix was to
    update the vendored regex library to the latest version. Issue affects
    versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior
    versions.
  * ClamOnAcc: Fixed a number of assorted stability issues and added
    niceties for debugging ClamOnAcc.
  * Fixed an issue causing byte-compare subsignatures to cause an alert
    when they match even if other conditions of the given logical
    signatures were not met.
  * Fix memleak when using multiple byte-compare subsignatures. This fix
    was backported from 0.104.0.
  * Assorted bug fixes and improvements.
- Remove upstreamed clamav-ck_assert_msg.patch

OBS-URL: https://build.opensuse.org/request/show/975241
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=232
2022-05-06 09:28:32 +00:00
Dominique Leuenberger
683d1c0d5b Accepting request 970848 from security
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/970848
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=117
2022-04-20 14:56:41 +00:00
39f7a7c432 - https source urls
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=230
2022-04-12 13:56:58 +00:00
Dominique Leuenberger
776304a29b Accepting request 946798 from security
OBS-URL: https://build.opensuse.org/request/show/946798
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=116
2022-01-16 22:18:32 +00:00
Reinhard Max
835832e4d1 Accepting request 945934 from home:adkorte:branches:security
- Update to 0.103.5
  * CVE-2022-20698: Fix for invalid pointer read that may cause a crash.
    This issue affects 0.104.1, 0.103.4 and prior when ClamAV is compiled
    with libjson-c and the CL_SCAN_GENERAL_COLLECT_METADATA scan option
    (the clamscan --gen-json option) is enabled.
  * Fixed ability to disable the file size limit with libclamav C API,
    like this:
      cl_engine_set_num(engine, CL_ENGINE_MAX_FILESIZE, 0);
    This issue didn't affect ClamD or ClamScan which also can disable the
    limit by setting it to zero using MaxFileSize 0 in clamd.conf for ClamD,
    or clamscan --max-filesize=0 for ClamScan.
    Note: Internally, the max file size is still set to 2 GiB. Disabling the
    limit for a scan will fall back on the internal 2 GiB limitation.
  * Increased the maximum line length for ClamAV config files from 512 bytes
    to 1,024 bytes to allow for longer config option strings.
  * SigTool: Fix insufficient buffer size for --list-sigs that caused a
    failure when listing a database containing one or more very long
    signatures. This fix was backported from 0.104.

OBS-URL: https://build.opensuse.org/request/show/945934
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=229
2022-01-16 14:09:37 +00:00
Dominique Leuenberger
af0b849f29 Accepting request 929611 from security
Fix some mistakes in the .changes file.

OBS-URL: https://build.opensuse.org/request/show/929611
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=115
2021-11-05 21:58:21 +00:00
Reinhard Max
95530f1fab OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=228 2021-11-05 08:56:31 +00:00
Reinhard Max
7cae9e815d OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=227 2021-11-05 08:25:43 +00:00
Reinhard Max
6feda178df Fix some mistakes in clamav.changes
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=226
2021-11-05 08:25:09 +00:00
Dominique Leuenberger
b958fb2021 Accepting request 929179 from security
OBS-URL: https://build.opensuse.org/request/show/929179
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=114
2021-11-04 15:42:16 +00:00
OBS User buildservice-autocommit
97d6c6c999 Updating link to change in openSUSE:Factory/clamav revision 114.0
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=622f6dcc0b0fb91c9834df4062134792
2021-11-04 15:42:16 +00:00
Reinhard Max
7c0f4d5fed - clamav-document-maxsize.patch: in the "clamscan" and "clamdscan" manpages,
document that files over a certain size by default will silently not be
  scanned and how this can be adjusted (bsc#1187509)
--------------------------------------------------------------------
- bsc#1192346: Update to 0.103.4
- bsc#1188284: Update to 0.103.3
  * obsoletes clamav-disable-timestamps.patch

OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=225
2021-11-04 13:53:57 +00:00
Reinhard Max
209db825f8 Accepting request 929092 from home:adkorte:branches:security
- Update to 0.103.4
  * FreshClam:
    - Add a 24-hour cool-down for FreshClam clients that have received
      an HTTP 403 (Forbidden) response from the CDN. This is to reduce
      the volume of 403-response data served to blocked FreshClam
      clients that are configured with a tight update-loop.
    - Fixed a bug where FreshClam treats an empty CDIFF as an
      incremental update failure instead of as an intentional request
      to download the whole CVD.
  * ClamDScan: Fix a scan error when broken symlinks are encountered on
    macOS with "FollowDirectorySymlinks" and "FollowFileSymlinks"
    options disabled.
  * Overhauled the scan recursion / nested archive extraction logic and
    added new limits on embedded file-type recognition performed during
    the "raw" scan of each file. This limits embedded file-type
    misidentification and prevents detecting embedded file content that
    is found/extracted and scanned at other layers in the scanning
    process.
  * Fix an issue with the FMap module that failed to read from some
    nested files.
  * Fixed an issue where failing to load some rules from a Yara file
    containing multiple rules may cause a crash.
  * Fixed assorted compiler warnings.
  * Fixed assorted Coverity static code analysis issues.
  * Scan limits:
    - Added virus-name suffixes to the alerts that trigger when a scan
      limit has been exceeded. Rather than simply
      Heuristics.Limits.Exceeded, you may now see limit-specific
      virus-names, to include:
      + Heuristics.Limits.Exceeded.MaxFileSize

OBS-URL: https://build.opensuse.org/request/show/929092
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=224
2021-11-04 13:14:31 +00:00