896f44d06a
- New version 1.3.2: * CVE-2024-20506: Changed the logging module to disable following symlinks on Linux and Unix systems so as to prevent an attacker with existing access to the 'clamd' or 'freshclam' services from using a symlink to corrupt system files. * CVE-2024-20505: Fixed a possible out-of-bounds read bug in the PDF file parser that could cause a denial-of-service condition. * Removed unused Python modules from freshclam tests including deprecated 'cgi' module that is expected to cause test failures in Python 3.13. * Fix unit test caused by expiring signing certificate. * Fixed a build issue on Windows with newer versions of Rust. Also upgraded GitHub Actions imports to fix CI failures. * Fixed an unaligned pointer dereference issue on select architectures. * Fixes to Jenkins CI pipeline. - Remove upstreamed 1305.patch OBS-URL: https://build.opensuse.org/request/show/1198813 OBS-URL: https://build.opensuse.org/package/show/security/clamav?expand=0&rev=263 |
||
---|---|---|
_constraints | ||
.gitattributes | ||
.gitignore | ||
1305.patch | ||
clamav-1.3.1.tar.gz | ||
clamav-1.3.1.tar.gz.sig | ||
clamav-1.3.2.tar.gz | ||
clamav-1.3.2.tar.gz.sig | ||
clamav-conf.patch | ||
clamav-document-maxsize.patch | ||
clamav-fips.patch | ||
clamav-format.patch | ||
clamav-obsolete-config.patch | ||
clamav-rpmlintrc | ||
clamav-tmpfiles.conf | ||
clamav.changes | ||
clamav.keyring | ||
clamav.spec | ||
service.clamav-milter | ||
service.clamd | ||
service.clamonacc | ||
service.freshclam | ||
system-user-vscan.conf | ||
timer.freshclam |