Описание
Recommended update for clamav
The antivirus scanner ClamAV has been updated to version 0.98.3, which includes the following fixes and enhancements:
Список пакетов
SUSE Linux Enterprise Desktop 11 SP3
SUSE Linux Enterprise Server 11 SP1-LTSS
SUSE Linux Enterprise Server 11 SP1-TERADATA
SUSE Linux Enterprise Server 11 SP2
SUSE Linux Enterprise Server 11 SP2-LTSS
SUSE Linux Enterprise Server 11 SP3
SUSE Linux Enterprise Server 11 SP3-TERADATA
SUSE Linux Enterprise Server for SAP Applications 11 SP2
SUSE Linux Enterprise Server for SAP Applications 11 SP3
Ссылки
- Link for SUSE-SU-2015:0298-1
- E-Mail link for SUSE-SU-2015:0298-1
- SUSE Security Ratings
- SUSE Bug 816865
- SUSE Bug 841815
- SUSE Bug 865883
- SUSE Bug 877475
- SUSE Bug 903489
- SUSE Bug 903719
- SUSE Bug 904207
- SUSE Bug 906077
- SUSE Bug 906770
- SUSE Bug 915512
- SUSE Bug 916214
- SUSE Bug 916215
- SUSE Bug 916217
- SUSE Bug 929192
- SUSE CVE CVE-2013-2020 page
- SUSE CVE CVE-2013-2021 page
- SUSE CVE CVE-2013-6497 page
Описание
Integer underflow in the cli_scanpe function in pe.c in ClamAV before 0.97.8 allows remote attackers to cause a denial of service (crash) via a skewed offset larger than the size of the PE section in a UPX packed executable, which triggers an out-of-bounds read.
Затронутые продукты
Ссылки
- CVE-2013-2020
- SUSE Bug 816865
- SUSE Bug 899395
Описание
pdf.c in ClamAV 0.97.1 through 0.97.7 allows remote attackers to cause a denial of service (out-of-bounds-read) via a crafted length value in an encrypted PDF file.
Затронутые продукты
Ссылки
- CVE-2013-2021
- SUSE Bug 816865
- SUSE Bug 899395
Описание
clamscan in ClamAV before 0.98.5, when using -a option, allows remote attackers to cause a denial of service (crash) as demonstrated by the jwplayer.js file.
Затронутые продукты
Ссылки
- CVE-2013-6497
- SUSE Bug 1040662
- SUSE Bug 906077
Описание
Heap-based buffer overflow in the cli_scanpe function in libclamav/pe.c in ClamAV before 0.98.5 allows remote attackers to cause a denial of service (crash) via a crafted y0da Crypter PE file.
Затронутые продукты
Ссылки
- CVE-2014-9050
- SUSE Bug 1040662
- SUSE Bug 906770
Описание
ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upack packer file, related to a "heap out of bounds condition."
Затронутые продукты
Ссылки
- CVE-2014-9328
- SUSE Bug 1040662
- SUSE Bug 915512
Описание
ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted (1) Yoda's crypter or (2) mew packer file, related to a "heap out of bounds condition."
Затронутые продукты
Ссылки
- CVE-2015-1461
- SUSE Bug 1040662
- SUSE Bug 916217
Описание
ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upx packer file, related to a "heap out of bounds condition."
Затронутые продукты
Ссылки
- CVE-2015-1462
- SUSE Bug 1040662
- SUSE Bug 916214
Описание
ClamAV before 0.98.6 allows remote attackers to cause a denial of service (crash) via a crafted petite packer file, related to an "incorrect compiler optimization."
Затронутые продукты
Ссылки
- CVE-2015-1463
- SUSE Bug 1040662
- SUSE Bug 916215
Описание
The upx decoder in ClamAV before 0.98.7 allows remote attackers to cause a denial of service (crash) via a crafted file.
Затронутые продукты
Ссылки
- CVE-2015-2170
- SUSE Bug 1040662
- SUSE Bug 921950
- SUSE Bug 922560
- SUSE Bug 929192
Описание
ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted y0da cryptor file.
Затронутые продукты
Ссылки
- CVE-2015-2221
- SUSE Bug 1040662
- SUSE Bug 921950
- SUSE Bug 922560
- SUSE Bug 929192
Описание
ClamAV before 0.98.7 allows remote attackers to cause a denial of service (crash) via a crafted petite packed file.
Затронутые продукты
Ссылки
- CVE-2015-2222
- SUSE Bug 1040662
- SUSE Bug 921950
- SUSE Bug 922560
- SUSE Bug 929192
Описание
Integer overflow in the regcomp implementation in the Henry Spencer BSD regex library (aka rxspencer) alpha3.8.g5 on 32-bit platforms, as used in NetBSD through 6.1.5 and other products, might allow context-dependent attackers to execute arbitrary code via a large regular expression that leads to a heap-based buffer overflow.
Затронутые продукты
Ссылки
- CVE-2015-2305
- SUSE Bug 1040662
- SUSE Bug 921950
- SUSE Bug 922022
- SUSE Bug 922028
- SUSE Bug 922030
- SUSE Bug 922043
- SUSE Bug 922560
- SUSE Bug 922567
- SUSE Bug 929192
- SUSE Bug 980366
Описание
ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted xz archive file.
Затронутые продукты
Ссылки
- CVE-2015-2668
- SUSE Bug 1040662
- SUSE Bug 921950
- SUSE Bug 922560
- SUSE Bug 929192