Bug 236818

Summary: security/clamav: Update to 0.101.2.
Product: Ports & Packages Reporter: Yasuhiro Kimura <yasu>
Component: Individual Port(s)Assignee: Steve Wills <swills>
Status: Closed FIXED    
Severity: Affects Many People CC: cgreen, danmcgrath.ca, nevecherya, philk, ports-secteam
Priority: Normal Keywords: security
Version: LatestFlags: yasu: merge-quarterly?
Hardware: Any   
OS: Any   
Bug Depends on: 236816    
Bug Blocks:    
Attachments:
Description Flags
Patch file yasu: maintainer-approval+

Description Yasuhiro Kimura freebsd_committer freebsd_triage 2019-03-27 03:27:00 UTC
Created attachment 203176 [details]
Patch file

Update to 0.101.2.

Security:
* CVE-2019-1785
* CVE-2019-1786
* CVE-2019-1787
* CVE-2019-1788
* CVE-2019-1789
* CVE-2019-1798
    
Bug #236816 describes above vulnerabilities. So please commit together.
Comment 1 cgreen 2019-04-10 17:12:28 UTC
ClamAV 0.101.2, the version fixing the security issues listed above, has been available for download for two weeks now, and the patch on this page was added only the day after that.

The bug describing the vulnerabilities was closed days ago, and the box I updated manually to this version seems to be running fine.

Is there any reason this updated version hasn't yet been pushed into the ports tree?
Comment 2 commit-hook freebsd_committer freebsd_triage 2019-04-11 00:56:56 UTC
A commit references this bug:

Author: swills
Date: Thu Apr 11 00:56:13 UTC 2019
New revision: 498628
URL: https://svnweb.freebsd.org/changeset/ports/498628

Log:
  security/clamav: Update to 0.101.2

  PR:		236818
  Submitted by:	Yasuhiro KIMURA <yasu@utahime.org> (maintainer)

Changes:
  head/security/clamav/Makefile
  head/security/clamav/distinfo
  head/security/clamav/pkg-plist
Comment 3 Steve Wills freebsd_committer freebsd_triage 2019-04-11 00:57:20 UTC
Committed, thanks!
Comment 4 philk 2019-06-01 03:37:42 UTC
Definitely not committed.

The version in the pkg repository is still 0.101.1,1

# pkg search clamav
clamav-0.101.1,1               Command line virus scanner written entirely in C

This has been known vulnerable for 2 months.
Comment 5 Kubilay Kocak freebsd_committer freebsd_triage 2019-06-12 13:35:46 UTC
*** Bug 238428 has been marked as a duplicate of this bug. ***
Comment 6 Kubilay Kocak freebsd_committer freebsd_triage 2019-06-12 13:36:33 UTC
Re-open for MFH
Comment 7 Danny McGrath 2019-06-14 14:10:44 UTC
Any chance of this fix getting ported to 2019Q2 soonish? Asking for a friend. :)
Comment 8 Yasuhiro Kimura freebsd_committer freebsd_triage 2019-08-01 11:48:14 UTC
There is already latest version (0.101.2) in latest quarterly branch (2019Q3).