Index: vuln.xml =================================================================== --- vuln.xml (revision 509380) +++ vuln.xml (working copy) @@ -58,6 +58,40 @@ * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + clamav -- multiple vulnerabilities + + + clamav + 0.101.4,1 + + + clamav-milter + 0.101.4,1 + + + + +

Micah Snyder reports:

+
+
    +
  • An out of bounds write was possible within ClamAV&s NSIS bzip2 library when attempting decompression in cases where the number of selectors exceeded the max limit set by the library (CVE-2019-12900). The issue has been resolved by respecting that limit.
  • +
  • The zip bomb vulnerability mitigated in 0.101.3 has been assigned the CVE identifier CVE-2019-12625. Unfortunately, a workaround for the zip-bomb mitigation was immediately identified. To remediate the zip-bomb scan time issue, a scan time limit has been introduced in 0.101.4. This limit now resolves ClamAV's vulnerability to CVE-2019-12625.
  • +
+
+ +
+ + https://blog.clamav.net/2019/08/clamav-01014-security-patch-release-has.html + CVE-2019-12625 + CVE-2019-12900 + + + 2019-08-21 + 2019-08-21 + +
+ nsd -- Stack-based Buffer Overflow