View | Details | Raw Unified | Return to bug 229649
Collapse All | Expand All

(-)vuln.xml (+34 lines)
Lines 58-63 Link Here
58
  * Do not forget port variants (linux-f10-libxml2, libxml2, etc.)
58
  * Do not forget port variants (linux-f10-libxml2, libxml2, etc.)
59
-->
59
-->
60
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
60
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
61
  <vuln vid="d1e9d8c5-839b-11e8-9610-9c5c8e75236a">
62
    <topic>clamav -- multiple vulnerabilities</topic>
63
    <affects>
64
      <package>
65
	<name>clamav</name>
66
	<range><lt>0.100.1</lt></range>
67
      </package>
68
    </affects>
69
    <description>
70
      <body xmlns="http://www.w3.org/1999/xhtml">
71
	<p> Joel Esler reports:</p>
72
	<blockquote cite="https://blog.clamav.net/2018/07/clamav-01001-has-been-released.html">
73
	  <p>3 security fixes in this release:</p>
74
	  <ul>
75
	    <li>CVE-2017-16932: Vulnerability in libxml2 dependency (affects ClamAV on Windows only).</li>
76
	    <li>CVE-2018-0360: HWP integer overflow, infinite loop vulnerability. Reported by Secunia Research at Flexera.</li>
77
	    <li>CVE-2018-0361: ClamAV PDF object length check, unreasonably long time to parse relatively small file. Report
78
ed by aCaB.</li>
79
	  </ul>
80
	</blockquote>
81
      </body>
82
    </description>
83
    <references>
84
      <url>https://blog.clamav.net/2018/07/clamav-01001-has-been-released.html</url>
85
      <cvename>CVE-2017-16932</cvename>
86
      <cvename>CVE-2018-0360</cvename>
87
      <cvename>CVE-2018-0361</cvename>
88
    </references>
89
    <dates>
90
      <discovery>2018-07-09</discovery>
91
      <entry>2018-07-09</entry>
92
    </dates>
93
  </vuln>
94
61
  <vuln vid="7764b219-8148-11e8-aa4d-000e0cd7b374">
95
  <vuln vid="7764b219-8148-11e8-aa4d-000e0cd7b374">
62
    <topic>zziplib - multiple vulnerabilities</topic>
96
    <topic>zziplib - multiple vulnerabilities</topic>
63
    <affects>
97
    <affects>

Return to bug 229649