Index: security/vuxml/vuln.xml =================================================================== --- security/vuxml/vuln.xml (revision 535073) +++ security/vuxml/vuln.xml (working copy) @@ -58,6 +58,44 @@ * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + clamav -- multiple vulnerabilities + + + clamav + 0.102.3,1 + + + + +

Micah Snyder reports:

+
+

CVE-2020-3327: Fixed a vulnerability in the ARJ archive-parsing module + in ClamAV 0.102.2 that could cause a denial-of-service condition. + Improper bounds checking of an unsigned variable results in an + out-of-bounds read which causes a crash. Special thanks to Daehui Chang + and Fady Othman for helping identify the ARJ parsing vulnerability. +

+

CVE-2020-3341: Fixed a vulnerability in the PDF-parsing module in ClamAV + 0.101 - 0.102.2 that could cause a denial-of-service condition. Improper + size checking of a buffer used to initialize AES decryption routines + results in an out-of-bounds read, which may cause a crash. OSS-Fuzz + discovered this vulnerability. +

+
+ +
+ + https://blog.clamav.net/2020/05/clamav-01023-security-patch-released.html + CVE-2020-3327 + CVE-2020-3341 + + + 2020-05-12 + 2020-05-14 + +
+ FreeBSD -- Insufficient cryptodev MAC key length check