UbuntuUpdates.org

Package "clamav"

Name: clamav

Description:

anti-virus utility for Unix - command-line interface

Latest version: 0.102.4+dfsg-0ubuntu0.16.04.1
Release: xenial (16.04)
Level: updates
Repository: main
Homepage: https://www.clamav.net/

Links


Download "clamav"


Other versions of "clamav" in Xenial

Repository Area Version
base main 0.99+dfsg-1ubuntu1
base universe 0.99+dfsg-1ubuntu1
security main 0.102.4+dfsg-0ubuntu0.16.04.1
security universe 0.102.4+dfsg-0ubuntu0.16.04.1
updates universe 0.102.4+dfsg-0ubuntu0.16.04.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 0.102.4+dfsg-0ubuntu0.16.04.1 2020-07-27 16:06:43 UTC

  clamav (0.102.4+dfsg-0ubuntu0.16.04.1) xenial-security; urgency=medium

  * Updated to 0.102.2 to fix security issues
    - debian/libclamav9.symbols: updated for new version.
    - debian/rules: bumped CL_FLEVEL to 115.
    - CVE-2020-3327
    - CVE-2020-3350
    - CVE-2020-3481

 -- Marc Deslauriers <email address hidden> Thu, 23 Jul 2020 09:08:18 -0400

Source diff to previous version
CVE-2020-3327 A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.2 could allow an unauthenticated, remote attacke
CVE-2020-3350 A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam AntiVirus could allow an authenticated, local attacker to cause the runn
CVE-2020-3481 A vulnerability in the EGG archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.0 - 0.102.3 could allow an unauthenticated, remo

Version: 0.102.3+dfsg-0ubuntu0.16.04.1 2020-05-21 18:06:31 UTC

  clamav (0.102.3+dfsg-0ubuntu0.16.04.1) xenial-security; urgency=medium

  * Updated to 0.102.2 to fix security issues
    - debian/libclamav9.symbols: updated for new version.
    - debian/rules: bumped CL_FLEVEL to 114.
    - CVE-2020-3327
    - CVE-2020-3341

 -- Marc Deslauriers <email address hidden> Tue, 19 May 2020 14:24:37 -0400

Source diff to previous version
CVE-2020-3327 A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.2 could allow an unauthenticated, remote attacke
CVE-2020-3341 A vulnerability in the PDF archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.101 - 0.102.2 could allow an unauthenticated, remote

Version: 0.102.2+dfsg-0ubuntu0.16.04.1 2020-02-18 15:07:07 UTC

  clamav (0.102.2+dfsg-0ubuntu0.16.04.1) xenial-security; urgency=medium

  * Updated to 0.102.2 to fix security issue (CVE-2020-3123)
    - debian/patches/*: synced patches with 0.102.2+dfsg-1.
    - debian/libclamav9.symbols: updated for new version.
    - debian/rules: bumped CL_FLEVEL to 113.

 -- Marc Deslauriers <email address hidden> Tue, 11 Feb 2020 08:45:45 -0500

Source diff to previous version
CVE-2020-3123 A vulnerability in the Data-Loss-Prevention (DLP) module in Clam AntiVirus (ClamAV) Software versions 0.102.1 and 0.102.0 could allow an unauthentica

Version: 0.102.1+dfsg-0ubuntu0.16.04.2 2020-01-08 16:06:59 UTC

  clamav (0.102.1+dfsg-0ubuntu0.16.04.2) xenial-security; urgency=medium

  * Updated to 0.102.1 to fix security issue (CVE-2019-15961)
    - debian/patches/*: synced patches with 0.102.1+dfsg-1ubuntu1.
    - debian/clamav-daemon.*.in,clamav-freshclam.*.in,
      clamav-daemon.templates: added new configuration options, dropped
      ClamOnAccess.
    - debian/clamav-deamon.install: install new clamonacc binary.
    - debian/clamav-docs.*: removed missing docs.
    - debian/libclamav9.install: added libfreshclam.so.2.
    - debian/libclamav9.symbols: updated for new version.
    - debian/rules: bumped CL_FLEVEL to 112.

 -- Marc Deslauriers <email address hidden> Tue, 07 Jan 2020 11:12:45 -0500

Source diff to previous version

Version: 0.101.4+dfsg-0ubuntu0.16.04.1 2019-10-02 13:07:06 UTC

  clamav (0.101.4+dfsg-0ubuntu0.16.04.1) xenial-security; urgency=medium

  * Updated to version 0.101.4 to fix security issues.
    - debian/patches/*: sync patches with 0.101.4+dfsg-1ubuntu1.
    - debian/clamav-daemon.postinst.in: removed DetectBrokenExecutables,
      added MaxScanTime, HeuristicAlerts, Alert*.
    - debian/*: updated for new library version.
    - debian/libclamav9.symbols: updated for new version.
    - debian/clamav-docs*, debian/rules: fix doc file locations.
    - debian/libclam-dev.install: include new header file.
    - debian/rules, debian/control: build with --with autoreconf.
    - CVE-2019-12625
    - CVE-2019-12900

 -- Marc Deslauriers <email address hidden> Tue, 24 Sep 2019 05:31:17 -0400

CVE-2019-12625 clamav zip DoS
CVE-2019-12900 BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.



About   -   Send Feedback to @ubuntu_updates