Commit Graph

182 Commits

Author SHA256 Message Date
3c1da791e3 Accepting request 601641 from security
- Update to version 0.100.0 (bsc#1089502):
  * Add interfaces to the Prelude SIEM open source package for
    collecting ClamAV virus events.
  * Support libmspack internal code or as a shared object
    library. The internal library is the default and includes
    modifications to enable parsing of CAB files that do not
    entirely adhere to the CAB file format.
  * Link with OpenSSL 1.1.0.
  * Deprecate of the AllowSupplementaryGroups parameter
    statement in clamd, clamav-milter, and freshclam.
    Use of supplementary is now in effect by default.
  * Deprecate internal LLVM code support.
  * Compute and check PE import table hash (a.k.a. "imphash")
    signatures.
  * Support file property collection and analysis for MHTML files.
  * Raw scanning of PostScript files.
  * Fix clamsubmit to use the new virus and false positive
    submission web interface.
  * Optionally, flag files with the virus
    "Heuristic.Limits.Exceeded" when size limitations are exceeded.
  * Improved decoders for PDF files.
  * Reduced number of compile time warnings.
  * Improved support for C++11.
  * Improved detection of system installed libraries.
  * Fixes to ClamAV's Container system and the introduction of
    Intermediates for more descriptive signatures.
  * Improvements to clamd's On-Access scanning capabilities
    for Linux.
  * Obsoletes clamav-fix_newer_zlib.patch
- Update key ring and add signature file.

OBS-URL: https://build.opensuse.org/request/show/601641
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=94
2018-04-29 17:37:28 +00:00
f1110218c2 - Turn off LLVM for now, because the bundled copy is deprecated,
the versions we have are too new and the performance gain over
  the  byte code interpreter are negligable, according to upstream.
- Put libclammspack0 into its own subpackage to follow the letter
  of the shlib packaging policy, even though it really makes no
  sense here.

OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=166
2018-04-26 15:39:59 +00:00
365105a77e - Move pkgconfig stuff from main to devel package.
- Re-introduce removed options as deprecated, so that clamd and
  freshclam don't exit on startup with an old config file
  (clamav-obsolete-config.patch).

OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=165
2018-04-18 14:49:27 +00:00
f9901db0ae OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=164 2018-04-18 11:48:19 +00:00
c0e27f9707 - On update, remove obsolete option SubmitDetectionStats from
/etc/freshclam.conf otherwise freshclam refuses to start.

OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=163
2018-04-18 08:35:09 +00:00
d2722d834a * Add interfaces to the Prelude SIEM open source package for
collecting ClamAV virus events.
  * Support libmspack internal code or as a shared object
    library. The internal library is the default and includes
    modifications to enable parsing of CAB files that do not
    entirely adhere to the CAB file format.
  * Link with OpenSSL 1.1.0.
  * Deprecate of the AllowSupplementaryGroups parameter
    statement in clamd, clamav-milter, and freshclam.
    Use of supplementary is now in effect by default.
  * Deprecate internal LLVM code support.
  * Compute and check PE import table hash (a.k.a. "imphash")
    signatures.
  * Support file property collection and analysis for MHTML files.
  * Raw scanning of PostScript files.
  * Fix clamsubmit to use the new virus and false positive
    submission web interface.
  * Optionally, flag files with the virus
    "Heuristic.Limits.Exceeded" when size limitations are exceeded.
  * Improved decoders for PDF files.
  * Reduced number of compile time warnings.
  * Improved support for C++11.
  * Improved detection of system installed libraries.
  * Fixes to ClamAV's Container system and the introduction of
    Intermediates for more descriptive signatures.
  * Improvements to clamd's On-Access scanning capabilities
    for Linux.
- Use system-wide LLVM instead of the deprecated bundled one.
- Move pkgconfig stuff the main to the devel package.

OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=162
2018-04-16 14:01:29 +00:00
506c87a397 - Update to version 0.100.0 (bsc#1089502):
* FIXME: Add upstream changes here before submitting to Factory.
  * Obsoletes clamav-fix_newer_zlib.patch
- Update key ring and add signature file.
- Remove the logic around building the embedded llvm as the
  system-wide llvm is now auto-detected and used.
- Move pc files from the main to the devel package.

OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=161
2018-04-13 15:16:49 +00:00
ec2a86b3ba Accepting request 583965 from security
- Update to security release 0.99.4 (bsc#1083915):
  * CVE-2012-6706
  * CVE-2017-6419
  * CVE-2017-11423
  * CVE-2018-1000085 (bsc#1082858)
  * CVE-2018-0202
- Obsolete patches:
  * clamav-CVE-2012-6706.patch
  * clamav-gcc47.patch

OBS-URL: https://build.opensuse.org/request/show/583965
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=93
2018-03-08 09:59:17 +00:00
1c2fe924d1 - Update to security release 0.99.4 (bsc#1083915):
* CVE-2012-6706
  * CVE-2017-6419
  * CVE-2017-11423
  * CVE-2018-1000085 (bsc#1082858)
  * CVE-2018-0202
- Obsolete patches:
  * clamav-CVE-2012-6706.patch
  * clamav-gcc47.patch

OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=159
2018-03-07 13:46:42 +00:00
777f113664 Accepting request 578702 from security
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/578702
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=92
2018-02-22 14:01:15 +00:00
5c457ced49 OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=157 2018-02-14 13:00:35 +00:00
469ac1b379 OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=156 2018-02-14 13:00:00 +00:00
55bf9502fd - Fix zlib version detection (clamav-zlib-version.patch).
- bsc#1045490, CVE-2012-6706: VMSF_DELTA filter in libclamunrar
  allows arbitrary memory write (clamav-CVE-2012-6706.patch).
- Buildrequire curl-devel to enable clamsubmit.

OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=155
2018-02-14 12:23:33 +00:00
8a49405b0e Accepting request 576419 from security
OBS-URL: https://build.opensuse.org/request/show/576419
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=91
2018-02-14 09:52:43 +00:00
0165340747 Accepting request 576006 from home:varkoly:branches:security
- bsc=983938 `After=syslog.target` left-overs in several unit files

OBS-URL: https://build.opensuse.org/request/show/576006
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=153
2018-02-14 00:04:03 +00:00
4ab94624a5 Accepting request 569980 from security
- Update to security release 0.99.3 (bsc#1077732)
  * CVE-2017-12376 (ClamAV Buffer Overflow in handle_pdfname Vulnerability)
  * CVE-2017-12377 (ClamAV Mew Packet Heap Overflow Vulnerability)
  * CVE-2017-12379 (ClamAV Buffer Overflow in messageAddArgument Vulnerability)
    - these vulnerabilities could have allowed an unauthenticated,
      remote attacker to cause a denial of service (DoS) condition
      or potentially execute arbitrary code on an affected device.
  * CVE-2017-12374 (ClamAV use-after-free Vulnerabilities)
  * CVE-2017-12375 (ClamAV Buffer Overflow Vulnerability)
  * CVE-2017-12378 (ClamAV Buffer Over Read Vulnerability)
  * CVE-2017-12380 (ClamAV Null Dereference Vulnerability)
    - these vulnerabilities could have allowed an unauthenticated,
      remote attacker to cause a denial of service (DoS) condition on an affected device.
  * CVE-2017-6420 (bsc#1052448)
    - this vulnerability allowed remote attackers to cause a denial of service
      (use-after-free) via a crafted PE file with WWPack compression.
  * CVE-2017-6419 (bsc#1052449)
    - ClamAV allowed remote attackers to cause a denial of service
      (heap-based buffer overflow and application crash) or possibly
      have unspecified other impact via a crafted CHM file.
  * CVE-2017-11423 (bsc#1049423)
    - The cabd_read_string function in mspack/cabd.c in libmspack 0.5alpha
      allowed remote attackers to cause a denial of service
      (stack-based buffer over-read and application crash) via a crafted CAB file.
  * CVE-2017-6418 (bsc#1052466)
    - ClamAV 0.99.2 allowed remote attackers to cause a denial
      of service (out-of-bounds read) via a crafted e-mail message.
- drop clamav-0.99.2-openssl-1.1.patch (upstream) (forwarded request 569976 from vitezslav_cizek)

OBS-URL: https://build.opensuse.org/request/show/569980
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=90
2018-01-28 19:32:09 +00:00
06d9b1e3a6 Accepting request 569976 from home:vitezslav_cizek:branches:security
- Update to security release 0.99.3 (bsc#1077732)
  * CVE-2017-12376 (ClamAV Buffer Overflow in handle_pdfname Vulnerability)
  * CVE-2017-12377 (ClamAV Mew Packet Heap Overflow Vulnerability)
  * CVE-2017-12379 (ClamAV Buffer Overflow in messageAddArgument Vulnerability)
    - these vulnerabilities could have allowed an unauthenticated,
      remote attacker to cause a denial of service (DoS) condition
      or potentially execute arbitrary code on an affected device.
  * CVE-2017-12374 (ClamAV use-after-free Vulnerabilities)
  * CVE-2017-12375 (ClamAV Buffer Overflow Vulnerability)
  * CVE-2017-12378 (ClamAV Buffer Over Read Vulnerability)
  * CVE-2017-12380 (ClamAV Null Dereference Vulnerability)
    - these vulnerabilities could have allowed an unauthenticated,
      remote attacker to cause a denial of service (DoS) condition on an affected device.
  * CVE-2017-6420 (bsc#1052448)
    - this vulnerability allowed remote attackers to cause a denial of service
      (use-after-free) via a crafted PE file with WWPack compression.
  * CVE-2017-6419 (bsc#1052449)
    - ClamAV allowed remote attackers to cause a denial of service
      (heap-based buffer overflow and application crash) or possibly
      have unspecified other impact via a crafted CHM file.
  * CVE-2017-11423 (bsc#1049423)
    - The cabd_read_string function in mspack/cabd.c in libmspack 0.5alpha
      allowed remote attackers to cause a denial of service
      (stack-based buffer over-read and application crash) via a crafted CAB file.
  * CVE-2017-6418 (bsc#1052466)
    - ClamAV 0.99.2 allowed remote attackers to cause a denial
      of service (out-of-bounds read) via a crafted e-mail message.
- drop clamav-0.99.2-openssl-1.1.patch (upstream)

OBS-URL: https://build.opensuse.org/request/show/569976
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=151
2018-01-26 16:21:11 +00:00
e8ca5e0b35 Accepting request 546176 from security
OBS-URL: https://build.opensuse.org/request/show/546176
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=89
2017-11-29 09:54:11 +00:00
0ec309c207 Accepting request 546167 from home:msmeissn:branches:security
- clamav-0.99.2-openssl-1.1.patch: fixed build against openssl 1.1

OBS-URL: https://build.opensuse.org/request/show/546167
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=149
2017-11-28 09:00:11 +00:00
e75b1e0316 Accepting request 532408 from security
1

OBS-URL: https://build.opensuse.org/request/show/532408
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=88
2017-10-09 17:44:11 +00:00
cb4029f851 Accepting request 521576 from home:jengelh:branches:security
- Implement shared library guideline.
+Change that old %makeinstall to modern %make_install

OBS-URL: https://build.opensuse.org/request/show/521576
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=147
2017-10-07 10:09:49 +00:00
a3e10d76a6 Accepting request 521169 from security
1

OBS-URL: https://build.opensuse.org/request/show/521169
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=87
2017-09-07 20:15:04 +00:00
aff26ed73c Accepting request 519486 from home:favogt:branches:security
- Add clamav-fix_newer_zlib.patch from ubuntu packages to fix build with
  zlib 1.2.11 (boo#1041201)

OBS-URL: https://build.opensuse.org/request/show/519486
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=145
2017-09-05 14:59:05 +00:00
Ruediger Oertel
dcb0ebcbe3 - pass --disable-zlib-vcheck to fix build in factory
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=144
2017-08-01 16:41:00 +00:00
d24defc9c8 Accepting request 499026 from home:AndreasStieger:branches:security
- provide and obsolete clamav-nodb to trigger it's removal in Leap
  bsc#1040662

OBS-URL: https://build.opensuse.org/request/show/499026
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=143
2017-05-29 18:25:35 +00:00
9c2e55a7f3 Accepting request 439839 from security
- Add enable-timestamps option to disable time
  dependent macros if passed to configure.
  (bsc#1001154, clamav-disable-timestamps.patch)

OBS-URL: https://build.opensuse.org/request/show/439839
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=86
2016-11-14 19:13:44 +00:00
8c0618ad69 dependent macros if passed to configure.
(bsc#1001154, clamav-disable-timestamps.patch)

OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=141
2016-11-11 08:40:20 +00:00
a52ab80012 Accepting request 439481 from home:faweiss:branches:security
OBS-URL: https://build.opensuse.org/request/show/439481
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=140
2016-11-10 22:34:49 +00:00
1d87629a77 Accepting request 416677 from security
- boo#991812: Remove obsolete dependency on latex2html-pngicons.
- Trim useless words from description and fix spellos.
  Test for user/group existence before adding and always show
  errors when they occur.

OBS-URL: https://build.opensuse.org/request/show/416677
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=85
2016-08-05 16:17:11 +00:00
8ffab86af0 - boo#991812: Remove obsolete dependency on latex2html-pngicons.
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=138
2016-08-03 09:03:14 +00:00
03195f5e0f Accepting request 414589 from home:jengelh:branches:security
- Trim useless words from description and fix spellos.
  Test for user/group existence before adding and always show
  errors when they occur.

OBS-URL: https://build.opensuse.org/request/show/414589
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=137
2016-07-29 11:05:50 +00:00
524d74b8af Accepting request 412572 from security
1

OBS-URL: https://build.opensuse.org/request/show/412572
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=84
2016-07-24 17:52:48 +00:00
87325daaab Accepting request 412543 from home:faweiss:branches:security
OBS-URL: https://build.opensuse.org/request/show/412543
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=135
2016-07-21 14:03:06 +00:00
bc6f51fc76 Accepting request 404154 from security
- Update to version 0.99.2 (bsc#978459)
  * 7z: fix for FolderStartPackStreamIndex array index heck
  * print all CDBNAME entries for a zip file when using the -z
    flag.
  * try to minimize the err cleanup path
  * clamunrar: notice if unpacking comment failed
  * signature manual update.
  * use temp var for realloc to prevent pointer loss.
  * fix debug VI hex truncation
  * freshclam: avoid random data in mirrors.dat.
  * libclamav: print raw certificate metadata
  * freshclam manager check return code of strdup.
  * additional suppress IP notification when using proxy
  * fix download and verification of *.cld through PrivateMirrors
  * suppress IP notification when using proxy
  * remove redundant mempool assignment
  * divide out dumpcerts output for better readability
  * fix dconf and option handling for nocert and dumpcert
  * patch by Jim Morris to increase clamd's soft file descriptor to
        its potential maximum on 64-bit systems
  * Move libfreshclam config to m4/reorganization.
  * adding libfreshclam
  * Add 'cdb' datafile to sigtools list of datafile types.
  * NULL pointer check.
  * malloc() NULL pointer check.
  * clamscan 'block-macros' option.
  * initialize cpio name buffer
  * initialize mspack decompression buffers
  * prevent memory allocations on used pointers (folder objects)
  * prevent memory allocations on used pointers (boolvectors)

OBS-URL: https://build.opensuse.org/request/show/404154
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=83
2016-06-25 00:22:48 +00:00
6a684a8b5a Fix sourc URL
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=133
2016-06-23 08:08:28 +00:00
474d811537 Accepting request 404152 from home:faweiss:branches:security
OBS-URL: https://build.opensuse.org/request/show/404152
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=132
2016-06-23 07:56:59 +00:00
3433687c6f Accepting request 403034 from security
1

OBS-URL: https://build.opensuse.org/request/show/403034
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=82
2016-06-19 10:52:58 +00:00
7988b83fbe Accepting request 402898 from home:marxin:branches:security
Change default C++ std to -std=gnu++98.

OBS-URL: https://build.opensuse.org/request/show/402898
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=130
2016-06-17 13:53:52 +00:00
f603bd111c Accepting request 367410 from security
1

OBS-URL: https://build.opensuse.org/request/show/367410
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=81
2016-03-08 08:39:15 +00:00
2043ee586a Accepting request 367392 from home:ecsos
update to 0.99.1, fix changelog

OBS-URL: https://build.opensuse.org/request/show/367392
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=128
2016-03-07 10:26:37 +00:00
cc65c20e57 Accepting request 353456 from security
1

OBS-URL: https://build.opensuse.org/request/show/353456
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=80
2016-01-15 09:41:40 +00:00
29ad975c7c Accepting request 350864 from home:msmeissn:branches:security
- now can handle regexp using signatures using pcre bsc#960237

OBS-URL: https://build.opensuse.org/request/show/350864
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=126
2016-01-13 18:12:46 +00:00
289bf3306d Accepting request 348647 from security
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/348647
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=79
2015-12-16 16:42:46 +00:00
0f7fe335ba Accepting request 347206 from security
1

OBS-URL: https://build.opensuse.org/request/show/347206
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=78
2015-12-06 06:41:03 +00:00
87cacf65b5 - Version 0.99 fixes bsc#957728.
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=123
2015-12-03 14:17:30 +00:00
a61d1ae6c8 Accepting request 347175 from home:posophe:branches:security
update + clean-up

OBS-URL: https://build.opensuse.org/request/show/347175
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=122
2015-12-02 16:24:31 +00:00
1a3fe256a2 Accepting request 314723 from security
1

OBS-URL: https://build.opensuse.org/request/show/314723
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=77
2015-07-02 20:50:45 +00:00
d1e009b238 Accepting request 314711 from home:pluskalm:branches:security
- Make clamd and clamav-milter services depend on freshclam as
  they need it

OBS-URL: https://build.opensuse.org/request/show/314711
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=120
2015-07-01 13:01:41 +00:00
Stephan Kulow
c1139d0047 Accepting request 305579 from security
- Version 0.98.7 fixes several security issues (bsc#929192) and
  other bug fixes/improvements:
  * Fix crash in upx decoder with crafted file. Discovered and
    patch supplied by Sebastian Andrzej Siewior. CVE-2015-2170.
  * Fix infinite loop condition on crafted y0da cryptor
    file. Identified and patch suggested by Sebastian Andrzej
    Siewior. CVE-2015-2221.
  * Fix crash on crafted petite packed file. Reported and patch
    supplied by Sebastian Andrzej Siewior. CVE-2015-2222.
  * Fix an infinite loop condition on a crafted "xz" archive file.
    This was reported by Dimitri Kirchner and Goulven Guiheux.
    CVE-2015-2668.
  * Apply upstream patch for possible heap overflow in Henry
    Spencer's regex library. CVE-2015-2305.
  * Fix false negatives on files within iso9660 containers. This
    issue was reported by Minzhuan Gong.
  * Fix a couple crashes on crafted upack packed file. Identified
    and patches supplied by Sebastian Andrzej Siewior.
  * Fix a crash during algorithmic detection on crafted PE file.
    Identified and patch supplied by Sebastian Andrzej Siewior.
  * Fix compilation error after ./configure --disable-pthreads.
    Reported and fix suggested by John E. Krokes.
  * Fix segfault scanning certain HTML files. Reported with sample
    by Kai Risku.
  * Improve detections within xar/pkg files.
  * Improvements to PDF processing: decryption, escape sequence
    handling, and file property collection.
  * Scanning/analysis of additional Microsoft Office 2003 XML
    format.

OBS-URL: https://build.opensuse.org/request/show/305579
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=76
2015-05-07 06:29:09 +00:00
116d5ae918 OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=118 2015-05-06 12:57:46 +00:00