Описание
Security update for clamav
clamav was updated to version 0.98.6 to fix four security issues.
These security issues were fixed:
- CVE-2015-1462: ClamAV allowed remote attackers to have unspecified impact via a crafted upx packer file, related to a heap out of bounds condition (bnc#916214).
- CVE-2015-1463: ClamAV allowed remote attackers to cause a denial of service (crash) via a crafted petite packer file, related to an incorrect compiler optimization (bnc#916215).
- CVE-2014-9328: ClamAV allowed remote attackers to have unspecified impact via a crafted upack packer file, related to a heap out of bounds condition (bnc#915512).
- CVE-2015-1461: ClamAV allowed remote attackers to have unspecified impact via a crafted (1) Yoda's crypter or (2) mew packer file, related to a heap out of bounds condition (bnc#916217).
Список пакетов
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
Ссылки
- Link for SUSE-SU-2015:0291-1
- E-Mail link for SUSE-SU-2015:0291-1
- SUSE Security Ratings
- SUSE Bug 915512
- SUSE Bug 916214
- SUSE Bug 916215
- SUSE Bug 916217
- SUSE CVE CVE-2014-9328 page
- SUSE CVE CVE-2015-1461 page
- SUSE CVE CVE-2015-1462 page
- SUSE CVE CVE-2015-1463 page
Описание
ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upack packer file, related to a "heap out of bounds condition."
Затронутые продукты
Ссылки
- CVE-2014-9328
- SUSE Bug 1040662
- SUSE Bug 915512
Описание
ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted (1) Yoda's crypter or (2) mew packer file, related to a "heap out of bounds condition."
Затронутые продукты
Ссылки
- CVE-2015-1461
- SUSE Bug 1040662
- SUSE Bug 916217
Описание
ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upx packer file, related to a "heap out of bounds condition."
Затронутые продукты
Ссылки
- CVE-2015-1462
- SUSE Bug 1040662
- SUSE Bug 916214
Описание
ClamAV before 0.98.6 allows remote attackers to cause a denial of service (crash) via a crafted petite packer file, related to an "incorrect compiler optimization."
Затронутые продукты
Ссылки
- CVE-2015-1463
- SUSE Bug 1040662
- SUSE Bug 916215