Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2023:3456-1

Опубликовано: 28 авг. 2023
Источник: suse-cvrf

Описание

Security update for clamav

This update for clamav fixes the following issues:

  • Update to 0.103.9
  • CVE-2023-20197: Fixed a possible denial of service vulnerability in the HFS+ file parser. (bsc#1214342)

Список пакетов

Image SLES15-SP1-SAP-Azure-LI-BYOS-Production
clamav-0.103.9-150000.3.47.1
libclamav9-0.103.9-150000.3.47.1
libfreshclam2-0.103.9-150000.3.47.1
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production
clamav-0.103.9-150000.3.47.1
libclamav9-0.103.9-150000.3.47.1
libfreshclam2-0.103.9-150000.3.47.1
Image SLES15-SP2-SAP-Azure-LI-BYOS-Production
clamav-0.103.9-150000.3.47.1
libclamav9-0.103.9-150000.3.47.1
libfreshclam2-0.103.9-150000.3.47.1
Image SLES15-SP2-SAP-Azure-VLI-BYOS-Production
clamav-0.103.9-150000.3.47.1
libclamav9-0.103.9-150000.3.47.1
libfreshclam2-0.103.9-150000.3.47.1
SUSE Enterprise Storage 7
clamav-0.103.9-150000.3.47.1
clamav-devel-0.103.9-150000.3.47.1
libclamav9-0.103.9-150000.3.47.1
libfreshclam2-0.103.9-150000.3.47.1
SUSE Enterprise Storage 7.1
clamav-0.103.9-150000.3.47.1
clamav-devel-0.103.9-150000.3.47.1
libclamav9-0.103.9-150000.3.47.1
libfreshclam2-0.103.9-150000.3.47.1
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS
clamav-0.103.9-150000.3.47.1
clamav-devel-0.103.9-150000.3.47.1
libclamav9-0.103.9-150000.3.47.1
libfreshclam2-0.103.9-150000.3.47.1
SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS
clamav-0.103.9-150000.3.47.1
clamav-devel-0.103.9-150000.3.47.1
libclamav9-0.103.9-150000.3.47.1
libfreshclam2-0.103.9-150000.3.47.1
SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS
clamav-0.103.9-150000.3.47.1
clamav-devel-0.103.9-150000.3.47.1
libclamav9-0.103.9-150000.3.47.1
libfreshclam2-0.103.9-150000.3.47.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
clamav-0.103.9-150000.3.47.1
clamav-devel-0.103.9-150000.3.47.1
libclamav9-0.103.9-150000.3.47.1
libfreshclam2-0.103.9-150000.3.47.1
SUSE Linux Enterprise Module for Basesystem 15 SP4
clamav-0.103.9-150000.3.47.1
clamav-devel-0.103.9-150000.3.47.1
libclamav9-0.103.9-150000.3.47.1
libfreshclam2-0.103.9-150000.3.47.1
SUSE Linux Enterprise Module for Basesystem 15 SP5
clamav-0.103.9-150000.3.47.1
clamav-devel-0.103.9-150000.3.47.1
libclamav9-0.103.9-150000.3.47.1
libfreshclam2-0.103.9-150000.3.47.1
SUSE Linux Enterprise Server 15 SP1-LTSS
clamav-0.103.9-150000.3.47.1
clamav-devel-0.103.9-150000.3.47.1
libclamav9-0.103.9-150000.3.47.1
libfreshclam2-0.103.9-150000.3.47.1
SUSE Linux Enterprise Server 15 SP2-LTSS
clamav-0.103.9-150000.3.47.1
clamav-devel-0.103.9-150000.3.47.1
libclamav9-0.103.9-150000.3.47.1
libfreshclam2-0.103.9-150000.3.47.1
SUSE Linux Enterprise Server 15 SP3-LTSS
clamav-0.103.9-150000.3.47.1
clamav-devel-0.103.9-150000.3.47.1
libclamav9-0.103.9-150000.3.47.1
libfreshclam2-0.103.9-150000.3.47.1
SUSE Linux Enterprise Server for SAP Applications 15 SP1
clamav-0.103.9-150000.3.47.1
clamav-devel-0.103.9-150000.3.47.1
libclamav9-0.103.9-150000.3.47.1
libfreshclam2-0.103.9-150000.3.47.1
SUSE Linux Enterprise Server for SAP Applications 15 SP2
clamav-0.103.9-150000.3.47.1
clamav-devel-0.103.9-150000.3.47.1
libclamav9-0.103.9-150000.3.47.1
libfreshclam2-0.103.9-150000.3.47.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3
clamav-0.103.9-150000.3.47.1
clamav-devel-0.103.9-150000.3.47.1
libclamav9-0.103.9-150000.3.47.1
libfreshclam2-0.103.9-150000.3.47.1
SUSE Manager Proxy 4.2
clamav-0.103.9-150000.3.47.1
clamav-devel-0.103.9-150000.3.47.1
libclamav9-0.103.9-150000.3.47.1
libfreshclam2-0.103.9-150000.3.47.1
SUSE Manager Server 4.2
clamav-0.103.9-150000.3.47.1
clamav-devel-0.103.9-150000.3.47.1
libclamav9-0.103.9-150000.3.47.1
libfreshclam2-0.103.9-150000.3.47.1
openSUSE Leap 15.4
clamav-0.103.9-150000.3.47.1
clamav-devel-0.103.9-150000.3.47.1
libclamav9-0.103.9-150000.3.47.1
libfreshclam2-0.103.9-150000.3.47.1
openSUSE Leap 15.5
clamav-0.103.9-150000.3.47.1
clamav-devel-0.103.9-150000.3.47.1
libclamav9-0.103.9-150000.3.47.1
libfreshclam2-0.103.9-150000.3.47.1

Описание

A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for completion when a file is decompressed, which may result in a loop condition that could cause the affected software to stop responding. An attacker could exploit this vulnerability by submitting a crafted HFS+ filesystem image to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to stop responding, resulting in a DoS condition on the affected software and consuming available system resources. For a description of this vulnerability, see the ClamAV blog .


Затронутые продукты
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production:clamav-0.103.9-150000.3.47.1
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production:libclamav9-0.103.9-150000.3.47.1
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production:libfreshclam2-0.103.9-150000.3.47.1
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production:clamav-0.103.9-150000.3.47.1

Ссылки
Уязвимость SUSE-SU-2023:3456-1