Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2023:3435-1

Опубликовано: 24 авг. 2023
Источник: suse-cvrf

Описание

Security update for clamav

This update for clamav fixes the following issues:

  • Update to 0.103.9
  • CVE-2023-20197: Fixed a possible denial of service vulnerability in the HFS+ file parser. (bsc#1214342)

Список пакетов

Image SLES12-SP5-SAP-Azure-LI-BYOS-Production
clamav-0.103.9-3.27.1
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production
clamav-0.103.9-3.27.1
SUSE Linux Enterprise Server 12 SP5
clamav-0.103.9-3.27.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5
clamav-0.103.9-3.27.1

Описание

A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for completion when a file is decompressed, which may result in a loop condition that could cause the affected software to stop responding. An attacker could exploit this vulnerability by submitting a crafted HFS+ filesystem image to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to stop responding, resulting in a DoS condition on the affected software and consuming available system resources. For a description of this vulnerability, see the ClamAV blog .


Затронутые продукты
Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:clamav-0.103.9-3.27.1
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:clamav-0.103.9-3.27.1
SUSE Linux Enterprise Server 12 SP5:clamav-0.103.9-3.27.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5:clamav-0.103.9-3.27.1

Ссылки