299 Commits

Author SHA256 Message Date
Ana Guerrero
ced495d4f9 Accepting request 1241514 from security
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/1241514
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=130
2025-01-31 15:04:55 +00:00
Reinhard Max
6c3f2d2904 - Drop the version dependency on libcurl. Building against versions
older than 7.45 does not fail anymore, but disables support for
  fdpassing in clamonacc. This only affects SLE-12 up to SP3.

OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=276
2025-01-23 17:37:45 +00:00
Ana Guerrero
fb4c75ee8e Accepting request 1239891 from security
Add missing bug and CVE references

- New version 1.4.2:
  * CVE-2025-20128, bsc#1236307: Fixed a possible buffer overflow
    read bug in the OLE2 file parser that could cause a
    denial-of-service (DoS) condition.  

    (bsc#1103032: CVE-2018-14679)
- Update to 0.103.7 (bsc#1202986)
    (the clamscan --gen-json option) is enabled. (bsc#1194731)
    clamdscan, and clamonacc. (bsc#1174255)
    parser in versions affected by the vulnerability. (bsc#1174250)
    a crash. (bsc#1171981)
  * CVE-2012-6706 (bsc#1045315)
  * CVE-2017-6419 (bsc#1052449)
  * CVE-2017-11423 (bsc#1049423)
  * CVE-2018-0202 (bsc#1083915)
- Update to version 0.99.1 (bsc#969814)
    (bnc#906770, CVE-2014-9050)

OBS-URL: https://build.opensuse.org/request/show/1239891
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=129
2025-01-23 17:03:00 +00:00
Reinhard Max
51084af50e Add missing bug and CVE references
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=274
2025-01-23 14:23:00 +00:00
Reinhard Max
163360e0f4 Add bug id
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=273
2025-01-23 12:26:03 +00:00
Reinhard Max
29a48de7ff - New version 1.4.2:
* CVE-2025-20128: Fixed a possible buffer overflow read bug in
    the OLE2 file parser that could cause a denial-of-service (DoS)
    condition.

OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=272
2025-01-22 18:21:29 +00:00
Ana Guerrero
f48e5bb1af Accepting request 1238512 from security
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/1238512
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=128
2025-01-17 17:43:50 +00:00
Reinhard Max
017c761fff - bsc#1232242: Start clamonacc with --fdpass to avoid errors due to
clamd not being able to access user files.

OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=270
2025-01-10 13:08:05 +00:00
Ana Guerrero
0c3339881d Accepting request 1231926 from security
- fix factory submission (clam.tcl, clamscan.log) (forwarded request 1231922 from AndreasStieger)

OBS-URL: https://build.opensuse.org/request/show/1231926
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=127
2024-12-18 19:11:19 +00:00
Reinhard Max
33b181b0e5 - fix factory submission (clam.tcl, clamscan.log)
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=268
2024-12-18 16:14:20 +00:00
Reinhard Max
7c9dfc0617 - fix factory submission (clam.tcl)
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=267
2024-12-18 13:56:22 +00:00
Reinhard Max
adb646ae3c OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=266 2024-09-10 14:24:43 +00:00
Reinhard Max
652f75b4ea OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=265 2024-09-10 13:46:52 +00:00
Reinhard Max
4be77ca9be - New version 1.4.1:
* [CVE-2024-20506, bsc#1230162]: Changed the logging module to
    disable following symlinks on Linux and Unix systems so as to
    prevent an attacker with existing access to the 'clamd' or
    'freshclam' services from using a symlink to corrupt system
    files.
  * [CVE-2024-20505, bsc#1230161]: Fixed a possible out-of-bounds
    read bug in the PDF file parser that could cause a
    denial-of-service (DoS) condition.
  * https://blog.clamav.net/2024/09/clamav-141-132-107-and-010312-security.html
- New version 1.4.0:
  * Added support for extracting ALZ archives.
  * Added support for extracting LHA/LZH archives.
  * Added the ability to disable image fuzzy hashing, if needed.
    For context, image fuzzy hashing is a detection mechanism
    useful for identifying malware by matching images included with
    the malware or phishing email/document.
  * https://blog.clamav.net/2024/08/clamav-140-feature-release-and-clamav.html

OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=264
2024-09-10 13:35:10 +00:00
Reinhard Max
896f44d06a Accepting request 1198813 from home:adkorte:branches:security
- New version 1.3.2:
  * CVE-2024-20506: Changed the logging module to disable following
    symlinks on Linux and Unix systems so as to prevent an attacker
    with existing access to the 'clamd' or 'freshclam' services from
    using a symlink to corrupt system files.
  * CVE-2024-20505: Fixed a possible out-of-bounds read bug in the PDF
    file parser that could cause a denial-of-service condition.
  * Removed unused Python modules from freshclam tests including
    deprecated 'cgi' module that is expected to cause test failures in
    Python 3.13.
  * Fix unit test caused by expiring signing certificate.
  * Fixed a build issue on Windows with newer versions of Rust. Also
    upgraded GitHub Actions imports to fix CI failures.
  * Fixed an unaligned pointer dereference issue on select architectures.
  * Fixes to Jenkins CI pipeline.
- Remove upstreamed 1305.patch

OBS-URL: https://build.opensuse.org/request/show/1198813
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=263
2024-09-09 12:39:53 +00:00
Dominique Leuenberger
5dcb5fee0f Accepting request 1190182 from security
OBS-URL: https://build.opensuse.org/request/show/1190182
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=126
2024-07-29 19:52:52 +00:00
Reinhard Max
9f8b189366 Add upstream 1305.patch to fix tests (boo#1102840, https://github.com/Cisco-Talos/clamav/issues/1300)
Note: it uses git apply for the binary patch of test.exe

OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=261
2024-07-29 08:05:33 +00:00
Ana Guerrero
37c4b40e34 Accepting request 1184343 from security
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/1184343
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=125
2024-07-02 16:17:36 +00:00
Reinhard Max
d5c48bd5cc OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=259 2024-06-24 15:32:35 +00:00
Reinhard Max
8604eed583 OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=258 2024-06-21 11:01:38 +00:00
Reinhard Max
dec2994d4b OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=257 2024-06-21 07:20:21 +00:00
Reinhard Max
697f22b85f OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=256 2024-06-20 13:25:04 +00:00
Reinhard Max
6671c35595 fix build on Factory
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=255
2024-06-19 15:20:48 +00:00
Reinhard Max
a7e3babd61 - New Version: 1.3.1:
* CVE-2024-20380: Fixed a possible crash in the HTML file parser
    that could cause a denial-of-service (DoS) condition.
  * Updated select Rust dependencies to the latest versions.
  * Fixed a bug causing some text to be truncated when converting
    from UTF-16.
  * Fixed assorted complaints identified by Coverity static
    analysis.
  * Fixed a bug causing CVDs downloaded by the DatabaseCustomURL
    Freshclam config option to be pruned and then re-downloaded
    with every update.
  * Added the new 'valhalla' database name to the list of optional
    databases in preparation for future work.
- Drop clamav-disable-yara.patch as yara cannot be disabled anymore

OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=254
2024-04-22 15:34:13 +00:00
Reinhard Max
4c0d696200 OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=253 2024-04-04 15:07:42 +00:00
Reinhard Max
9f7e5bf9ea Accepting request 1161540 from home:rmax:branches:security
- New version: 1.3.0:
  * Added support for extracting and scanning attachments found in
    Microsoft OneNote section files. OneNote parsing will be
    enabled by default, but may be optionally disabled.
  * Added file type recognition for compiled Python (`.pyc`) files.
  * Improved support for decrypting PDFs with empty passwords.
  * Fixed a warning when scanning some HTML files.
  * ClamOnAcc: Fixed an infinite loop when a watched directory
    does not exist.
  * ClamOnAcc: Fixed an infinite loop when a file has been deleted
    before a scan.
- Use %patch -P N instead of deprecated %patchN.
- New version: 1.2.0:
  * Added support for extracting Universal Disk Format (UDF)
    partitions.
  * Added an option to customize the size of ClamAV's clean file
    cache.
  * Raised the MaxScanSize limit so the total amount of data
    scanned when scanning a file or archive may exceed 4 gigabytes.
  * Added ability for Freshclam to use a client certificate PEM
    file and a private key PEM file for authentication to a private
    mirror.
  * Fix an issue extracting files from ISO9660 partitions where the
    files are listed in the plain ISO tree and there also exists an
    empty Joliet tree.
  * PID and socket are now located under /run/clamav/clamd.pid and
    /run/clamav/clamd.sock .
  * bsc#1211594: Fixed an issue where ClamAV does not abort the
    signature load process after partially loading an invalid
    signature.

OBS-URL: https://build.opensuse.org/request/show/1161540
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=252
2024-03-25 18:13:50 +00:00
Ana Guerrero
d25fefd232 Accepting request 1151661 from security
OBS-URL: https://build.opensuse.org/request/show/1151661
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=124
2024-02-26 18:48:32 +00:00
Reinhard Max
393ffa0338 Accepting request 1151087 from home:dimstar:rpm4.20:c
Prepare for RPM 4.20

OBS-URL: https://build.opensuse.org/request/show/1151087
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=250
2024-02-26 13:52:49 +00:00
Ana Guerrero
6c8eaf7217 Accepting request 1122919 from security
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/1122919
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=123
2023-11-02 19:23:16 +00:00
Reinhard Max
9ebe900e55 Add bugzilla and CVE reference
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=248
2023-10-26 15:45:16 +00:00
Ana Guerrero
09d196dae1 Accepting request 1120590 from security
OBS-URL: https://build.opensuse.org/request/show/1120590
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=122
2023-10-26 15:15:20 +00:00
Reinhard Max
d4f9bd6fc9 Accepting request 1120366 from home:adkorte:branches:security
- Update to 0.103.11
  * Upgrade the bundled UnRAR library (libclamunrar) to version 6.2.12.
  * Windows: libjson-c 0.17 compatibility fix. with ssize_t type definition.
  * Windows: Update build system to use OpenSSL 3 and PThreads-Win32 v3.
- Update to 0.103.10
  * Upgrade the bundled UnRAR library (libclamunrar) to version 6.2.10.

OBS-URL: https://build.opensuse.org/request/show/1120366
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=246
2023-10-26 13:32:31 +00:00
Ana Guerrero
2ae20ef73b Accepting request 1105919 from security
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/1105919
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=121
2023-08-28 15:13:25 +00:00
Reinhard Max
f750401fdc OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=244 2023-08-18 14:03:24 +00:00
Reinhard Max
6bdefd2c39 OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=243 2023-08-18 14:00:53 +00:00
Reinhard Max
0c1991c29e - Renew clamav.keyring .
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=242
2023-08-18 13:19:37 +00:00
Reinhard Max
79bdf6ebb0 Accepting request 1104230 from home:adkorte:branches:security
- Update to 0.103.9
  * CVE-2023-20197: Fixed a possible denial of service vulnerability in
    the HFS+ file parser. This issue affects versions 1.1.0, 1.0.1 through
    1.0.0, 0.105.2 through 0.105.0, 0.104.4 through 0.104.0, and 0.103.8
    through 0.103.0. (boo#1214342)
  * Fixed compiler warnings that may turn into errors in Clang 16.

OBS-URL: https://build.opensuse.org/request/show/1104230
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=241
2023-08-16 18:49:44 +00:00
Dominique Leuenberger
229d0e65c5 Accepting request 1066149 from security
- Update to 0.103.8
  * CVE-2023-20032: Fixed a possible remote code execution vulnerability
    in the HFS+ file parser. Issue affects versions 1.0.0 and earlier,
    0.105.1 and earlier, and 0.103.7 and earlier. (bsc#1208363)
  * CVE-2023-20052: Fixed a possible remote information leak
    vulnerability in the DMG file parser. Issue affects versions 1.0.0
    and earlier, 0.105.1 and earlier, and 0.103.7 and earlier.
    (bsc#1208365)
  * Update vendored libmspack library to version 0.11alpha.
- Package huge .html documentation in a separate subpackage.

OBS-URL: https://build.opensuse.org/request/show/1066149
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=120
2023-02-16 15:57:09 +00:00
Reinhard Max
8dcf736f6a 0.105.1 and earlier, and 0.103.7 and earlier. (bsc#1208363)
(bsc#1208365)

OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=239
2023-02-16 10:21:28 +00:00
Reinhard Max
2efd340a5a Accepting request 1066029 from home:adkorte:branches:security
- Update to 0.103.8
  * CVE-2023-20032: Fixed a possible remote code execution vulnerability
    in the HFS+ file parser. Issue affects versions 1.0.0 and earlier,
    0.105.1 and earlier, and 0.103.7 and earlier.
  * CVE-2023-20052: Fixed a possible remote information leak
    vulnerability in the DMG file parser. Issue affects versions 1.0.0
    and earlier, 0.105.1 and earlier, and 0.103.7 and earlier.
  * Update vendored libmspack library to version 0.11alpha.
- Package huge .html documentation in a separate subpackage.

OBS-URL: https://build.opensuse.org/request/show/1066029
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=238
2023-02-16 09:53:43 +00:00
Dominique Leuenberger
412e335eb2 Accepting request 993801 from security
OBS-URL: https://build.opensuse.org/request/show/993801
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=119
2022-08-09 13:27:30 +00:00
Reinhard Max
35824f3ad3 Accepting request 993249 from home:ecsos
- Update to 0.103.7
  - Zip parser: tolerate 2-byte overlap in file entries
  - Fix bug with logical signature Intermediates feature
  - Update to UnRAR v6.1.7
  - Patch UnRAR: allow skipping files in solid archives
  - Patch UnRAR: limit dict winsize to 1GB

OBS-URL: https://build.opensuse.org/request/show/993249
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=236
2022-08-08 14:18:42 +00:00
Dominique Leuenberger
a5795499ce Accepting request 975373 from security
update clamav to 0.103.6

OBS-URL: https://build.opensuse.org/request/show/975373
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=118
2022-05-06 16:59:55 +00:00
Robert Frohl
17cc3145e0 created new boo# for missing CVE
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=234
2022-05-06 09:39:17 +00:00
Robert Frohl
42d69218c0 add missing boo#
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=233
2022-05-06 09:32:31 +00:00
Robert Frohl
a2ea93b424 Accepting request 975241 from home:adkorte:branches:security
- Update to 0.103.6
  * CVE-2022-20770: Fixed a possible infinite loop vulnerability in the CHM
    file parser. Issue affects versions 0.104.0 through 0.104.2 and LTS
    version 0.103.5 and prior versions.
  * CVE-2022-20796: Fixed a possible NULL-pointer dereference crash in the
    scan verdict cache check. Issue affects versions 0.103.4, 0.103.5,
    0.104.1, and 0.104.2.
  * CVE-2022-20771: Fixed a possible infinite loop vulnerability in the
    TIFF file parser. Issue affects versions 0.104.0 through 0.104.2 and
    LTS version 0.103.5 and prior versions. The issue only occurs if the
    "--alert-broken-media" ClamScan option is enabled. For ClamD, the
    affected option is "AlertBrokenMedia yes", and for libclamav it is the
    "CL_SCAN_HEURISTIC_BROKEN_MEDIA" scan option.
  * CVE-2022-20785: Fixed a possible memory leak in the HTML file parser /
    Javascript normalizer. Issue affects versions 0.104.0 through 0.104.2
    and LTS version 0.103.5 and prior versions.
  * CVE-2022-20792: Fixed a possible multi-byte heap buffer overflow write
    vulnerability in the signature database load module. The fix was to
    update the vendored regex library to the latest version. Issue affects
    versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior
    versions.
  * ClamOnAcc: Fixed a number of assorted stability issues and added
    niceties for debugging ClamOnAcc.
  * Fixed an issue causing byte-compare subsignatures to cause an alert
    when they match even if other conditions of the given logical
    signatures were not met.
  * Fix memleak when using multiple byte-compare subsignatures. This fix
    was backported from 0.104.0.
  * Assorted bug fixes and improvements.
- Remove upstreamed clamav-ck_assert_msg.patch

OBS-URL: https://build.opensuse.org/request/show/975241
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=232
2022-05-06 09:28:32 +00:00
Dominique Leuenberger
683d1c0d5b Accepting request 970848 from security
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/970848
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=117
2022-04-20 14:56:41 +00:00
39f7a7c432 - https source urls
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=230
2022-04-12 13:56:58 +00:00
Dominique Leuenberger
776304a29b Accepting request 946798 from security
OBS-URL: https://build.opensuse.org/request/show/946798
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/clamav?expand=0&rev=116
2022-01-16 22:18:32 +00:00
Reinhard Max
835832e4d1 Accepting request 945934 from home:adkorte:branches:security
- Update to 0.103.5
  * CVE-2022-20698: Fix for invalid pointer read that may cause a crash.
    This issue affects 0.104.1, 0.103.4 and prior when ClamAV is compiled
    with libjson-c and the CL_SCAN_GENERAL_COLLECT_METADATA scan option
    (the clamscan --gen-json option) is enabled.
  * Fixed ability to disable the file size limit with libclamav C API,
    like this:
      cl_engine_set_num(engine, CL_ENGINE_MAX_FILESIZE, 0);
    This issue didn't affect ClamD or ClamScan which also can disable the
    limit by setting it to zero using MaxFileSize 0 in clamd.conf for ClamD,
    or clamscan --max-filesize=0 for ClamScan.
    Note: Internally, the max file size is still set to 2 GiB. Disabling the
    limit for a scan will fall back on the internal 2 GiB limitation.
  * Increased the maximum line length for ClamAV config files from 512 bytes
    to 1,024 bytes to allow for longer config option strings.
  * SigTool: Fix insufficient buffer size for --list-sigs that caused a
    failure when listing a database containing one or more very long
    signatures. This fix was backported from 0.104.

OBS-URL: https://build.opensuse.org/request/show/945934
OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=229
2022-01-16 14:09:37 +00:00