4be77ca9be- New version 1.4.1: * [CVE-2024-20506, bsc#1230162]: Changed the logging module to disable following symlinks on Linux and Unix systems so as to prevent an attacker with existing access to the 'clamd' or 'freshclam' services from using a symlink to corrupt system files. * [CVE-2024-20505, bsc#1230161]: Fixed a possible out-of-bounds read bug in the PDF file parser that could cause a denial-of-service (DoS) condition. * https://blog.clamav.net/2024/09/clamav-141-132-107-and-010312-security.html - New version 1.4.0: * Added support for extracting ALZ archives. * Added support for extracting LHA/LZH archives. * Added the ability to disable image fuzzy hashing, if needed. For context, image fuzzy hashing is a detection mechanism useful for identifying malware by matching images included with the malware or phishing email/document. * https://blog.clamav.net/2024/08/clamav-140-feature-release-and-clamav.html
Reinhard Max
2024-09-10 13:35:10 +0000
896f44d06aAccepting request 1198813 from home:adkorte:branches:security
Reinhard Max
2024-09-09 12:39:53 +0000
5dcb5fee0fAccepting request 1190182 from security
Dominique Leuenberger
2024-07-29 19:52:52 +0000
6671c35595fix build on Factory
Reinhard Max
2024-06-19 15:20:48 +0000
a7e3babd61- New Version: 1.3.1: * CVE-2024-20380: Fixed a possible crash in the HTML file parser that could cause a denial-of-service (DoS) condition. * Updated select Rust dependencies to the latest versions. * Fixed a bug causing some text to be truncated when converting from UTF-16. * Fixed assorted complaints identified by Coverity static analysis. * Fixed a bug causing CVDs downloaded by the DatabaseCustomURL Freshclam config option to be pruned and then re-downloaded with every update. * Added the new 'valhalla' database name to the list of optional databases in preparation for future work. - Drop clamav-disable-yara.patch as yara cannot be disabled anymore
Reinhard Max
2024-04-22 15:34:13 +0000
6feda178dfFix some mistakes in clamav.changes
Reinhard Max
2021-11-05 08:25:09 +0000
b958fb2021Accepting request 929179 from security
Dominique Leuenberger
2021-11-04 15:42:16 +0000
97d6c6c999Updating link to change in openSUSE:Factory/clamav revision 114.0
OBS User buildservice-autocommit
2021-11-04 15:42:16 +0000
7c0f4d5fed- clamav-document-maxsize.patch: in the "clamscan" and "clamdscan" manpages, document that files over a certain size by default will silently not be scanned and how this can be adjusted (bsc#1187509) -------------------------------------------------------------------- - bsc#1192346: Update to 0.103.4 - bsc#1188284: Update to 0.103.3 * obsoletes clamav-disable-timestamps.patch
Reinhard Max
2021-11-04 13:53:57 +0000
209db825f8Accepting request 929092 from home:adkorte:branches:security
Reinhard Max
2021-11-04 13:14:31 +0000
23843d8c69Accepting request 902389 from security
Dominique Leuenberger
2021-06-26 19:25:26 +0000
67f2541c68Accepting request 901217 from home:adkorte
Reinhard Max
2021-06-25 13:36:20 +0000
b8014be1bdAccepting request 884035 from security
Richard Brown
2021-04-10 13:27:51 +0000
75371112e9- Use a split-provides for clamav-milter instead of recommending it.
Reinhard Max
2021-04-09 10:35:14 +0000
aea56be75c* CVE-2021-1252, bsc#1184532: Fix for Excel XLM parser infinite loop. Affects 0.103.0 and 0.103.1 only. * CVE-2021-1404, bsc#1184533: Fix for PDF parser buffer over-read; possible crash. Affects 0.103.0 and 0.103.1 only. * CVE-2021-1405, bsc#1184534: Fix for mail parser NULL-dereference crash. Affects 0.103.1 and prior. * bsc#1181256: Fix errors when scanning files > 4G
Reinhard Max
2021-04-09 08:50:38 +0000
b6dec3dc1bAccepting request 883689 from home:adkorte
Reinhard Max
2021-04-08 08:27:46 +0000
50d583a507Accepting request 871162 from home:adkorte
Reinhard Max
2021-02-22 18:54:31 +0000
eae6800d40Accepting request 870558 from security
Dominique Leuenberger
2021-02-09 20:17:31 +0000
d2b70b567cAccepting request 869944 from home:adkorte:branches:security
Reinhard Max
2021-02-09 14:32:05 +0000
c4f8c05b69Accepting request 848312 from security
Dominique Leuenberger
2020-11-13 18:00:07 +0000
bdee1c074bAdd missing bug references
Reinhard Max
2020-11-13 08:38:37 +0000
0112d10828Accepting request 848100 from home:dimstar:Factory
Reinhard Max
2020-11-13 08:23:03 +0000
f86351c0e0- Sync Factory to SLE-15 to implement jsc#ECO-3010.
Reinhard Max
2020-11-11 10:16:08 +0000
7632c657ae- bsc#1119353, clamav-fips.patch: Fix freshclam crash in FIPS mode. - Keep OBS from installing an existing clamav instance to scan the sources, because this makes "make check" use the old library instead of the just built one. This is only a workaround until we found a way to keep libtool from adding libdir to rpath and LD_LIBRARY_PATH of the binaries in the testsuite.
Reinhard Max
2020-11-10 16:48:44 +0000
35f7bc9f0fAccepting request 835433 from security
Dominique Leuenberger
2020-09-21 15:33:23 +0000
7a7a40f392Accepting request 834369 from home:adkorte:branches:security
Reinhard Max
2020-09-18 14:19:44 +0000
52608c0d9aAccepting request 821532 from security
Dominique Leuenberger
2020-07-17 18:54:14 +0000
a77e16ba02Accepting request 821356 from home:adkorte
Reinhard Max
2020-07-17 14:24:02 +0000
4d7c445036Accepting request 803386 from security
Dominique Leuenberger
2020-05-12 20:36:38 +0000
1c959d22c6Accepting request 803374 from home:adkorte
Reinhard Max
2020-05-12 18:00:54 +0000
37878bbf5dAccepting request 794379 from security
Dominique Leuenberger
2020-04-16 21:04:37 +0000
2f95031a55Accepting request 790518 from home:pluskalm:branches:security
Lars Vogdt
2020-04-15 20:39:04 +0000
90d854bc00Accepting request 770647 from security
Dominique Leuenberger
2020-02-07 14:54:44 +0000
201de5a035Accepting request 770381 from home:adkorte:branches:security
Reinhard Max
2020-02-06 15:31:51 +0000
20780f58f1Accepting request 759922 from security
Dominique Leuenberger
2019-12-30 11:35:04 +0000
cbdea8fb88Accepting request 759130 from home:adkorte:branches:security
Lars Vogdt
2019-12-29 17:31:13 +0000
6b04af4a48Accepting request 759585 from security
Dominique Leuenberger
2019-12-27 12:50:27 +0000
390db3b64fAccepting request 758279 from security
OBS User buildservice-autocommit
2019-12-21 11:31:09 +0000
02e349c676Accepting request 758279 from security
Dominique Leuenberger
2019-12-21 11:31:08 +0000
ea7676f3e7Updating link to change in openSUSE:Factory/clamav revision 102.0
OBS User buildservice-autocommit
2019-12-21 11:31:08 +0000
0a88f93182Accepting request 758289 from home:dimstar:Factory
Lars Vogdt
2019-12-19 16:37:55 +0000
985996eda4Accepting request 758248 from home:dimstar:Factory
Robert Frohl
2019-12-19 15:48:53 +0000
4ea5453cceAccepting request 750886 from security
Dominique Leuenberger
2019-11-26 16:02:30 +0000
419e234024Accepting request 750749 from home:adkorte:branches:security
Lars Vogdt
2019-11-25 23:01:55 +0000
0fad9da013Accepting request 742982 from security
Dominique Leuenberger
2019-10-27 12:40:55 +0000
61f3c20dcc- bsc#1151839: Increase the startup timeout of clamd to 5 minutes to cater for the grown virus database as a workaround until clamd has learned to talk to systemd to extend the timeout as long as needed.
Reinhard Max
2019-10-25 14:54:38 +0000
212af0f0b6Accepting request 729457 from security
Dominique Leuenberger
2019-09-09 21:59:38 +0000
2f65992cdbAccepting request 728340 from home:AndreasStieger:branches:securityMarcus Meissner2019-09-09 12:39:48 +0000
9828f8030eAccepting request 721852 from security
Dominique Leuenberger
2019-08-09 14:54:09 +0000
ce9e01186a- Update to version 0.101.3: * bsc#1144504: ZIP bomb causes extreme CPU spikes
Reinhard Max
2019-08-08 06:51:13 +0000
d88a0e4e4cAccepting request 689824 from security
Dominique Leuenberger
2019-04-04 13:22:20 +0000
e938462aa4silently adopt sr#689821.
Reinhard Max
2019-03-29 12:20:19 +0000
b5b97e006a* CVE-2019-1786: An out-of-bounds heap read condition may occur when scanning malformed PDF documents as a result of improper bounds-checking. * CVE-2019-1785: A path-traversal write condition may occur as a result of improper input validation when scanning RAR archives. * CVE-2019-1798: A use-after-free condition may occur as a result of improper error handling when scanning nested RAR archives. * Add missing headers to fix build of packages against libclamav.
Reinhard Max
2019-03-29 12:01:14 +0000
862d152324Accepting request 689169 from home:EGDFree:branches:securityMarcus Meissner2019-03-29 10:03:13 +0000
72865bd263- Update to version 0.101.1: * more details will be added later - Add missing include for str.h to libclamav/others_common.c (clamav-str-h.patch)
Reinhard Max
2019-01-21 17:35:52 +0000
7448ab81aaAccepting request 639958 from security
Dominique Leuenberger
2018-10-04 17:03:24 +0000
b00c83a767whitespace
Reinhard Max
2018-10-04 10:01:56 +0000
16df387343- Update to version 0.100.2: * bsc#1110723, CVE-2018-15378: Vulnerability in ClamAV's MEW unpacking feature that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. * bsc#1103040, CVE-2018-14680, CVE-2018-14681, CVE-2018-14682: more fixes for embedded libmspack. * Make freshclam more robust against lagging signature mirrors. * On-Access "Extra Scanning", an opt-in minor feature of OnAccess scanning on Linux systems, has been disabled due to a known issue with resource cleanup OnAccessExtraScanning will be re-enabled in a future release when the issue is resolved. In the mean-time, users who enabled the feature in clamd.conf will see a warning informing them that the feature is not active. For details, see: https://bugzilla.clamav.net/show_bug.cgi?id=12048 - Restore exit code compatibility of freshclam with versions before 0.100.0 when the virus database is already up to date (bsc#1104457, clamav-freshclam-exit.patch).
Reinhard Max
2018-10-04 09:52:49 +0000