UbuntuUpdates.org

Package "clamav"

Name: clamav

Description:

anti-virus utility for Unix - command-line interface

Latest version: 0.103.8+dfsg-0ubuntu0.18.04.1
Release: bionic (18.04)
Level: security
Repository: main
Homepage: https://www.clamav.net/

Links


Download "clamav"


Other versions of "clamav" in Bionic

Repository Area Version
base main 0.99.4+addedllvm-0ubuntu1
base universe 0.99.4+addedllvm-0ubuntu1
security universe 0.103.8+dfsg-0ubuntu0.18.04.1
updates universe 0.103.8+dfsg-0ubuntu0.18.04.1
updates main 0.103.8+dfsg-0ubuntu0.18.04.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 0.102.4+dfsg-0ubuntu0.18.04.1 2020-07-27 16:06:47 UTC

  clamav (0.102.4+dfsg-0ubuntu0.18.04.1) bionic-security; urgency=medium

  * Updated to 0.102.2 to fix security issues
    - debian/libclamav9.symbols: updated for new version.
    - debian/rules: bumped CL_FLEVEL to 115.
    - CVE-2020-3327
    - CVE-2020-3350
    - CVE-2020-3481

 -- Marc Deslauriers <email address hidden> Thu, 23 Jul 2020 09:08:18 -0400

Source diff to previous version
CVE-2020-3327 A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.2 could allow an unauthenticated, remote attacke
CVE-2020-3350 A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam AntiVirus could allow an authenticated, local attacker to cause the runn
CVE-2020-3481 A vulnerability in the EGG archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.0 - 0.102.3 could allow an unauthenticated, remo

Version: 0.102.3+dfsg-0ubuntu0.18.04.1 2020-05-21 18:06:36 UTC

  clamav (0.102.3+dfsg-0ubuntu0.18.04.1) bionic-security; urgency=medium

  * Updated to 0.102.2 to fix security issues
    - debian/libclamav9.symbols: updated for new version.
    - debian/rules: bumped CL_FLEVEL to 114.
    - CVE-2020-3327
    - CVE-2020-3341

 -- Marc Deslauriers <email address hidden> Tue, 19 May 2020 14:24:37 -0400

Source diff to previous version
CVE-2020-3327 A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.2 could allow an unauthenticated, remote attacke
CVE-2020-3341 A vulnerability in the PDF archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.101 - 0.102.2 could allow an unauthenticated, remote

Version: 0.102.2+dfsg-0ubuntu0.18.04.1 2020-02-18 14:07:42 UTC

  clamav (0.102.2+dfsg-0ubuntu0.18.04.1) bionic-security; urgency=medium

  * Updated to 0.102.2 to fix security issue (CVE-2020-3123)
    - debian/patches/*: synced patches with 0.102.2+dfsg-1.
    - debian/libclamav9.symbols: updated for new version.
    - debian/rules: bumped CL_FLEVEL to 113.

 -- Marc Deslauriers <email address hidden> Tue, 11 Feb 2020 08:45:45 -0500

Source diff to previous version
CVE-2020-3123 A vulnerability in the Data-Loss-Prevention (DLP) module in Clam AntiVirus (ClamAV) Software versions 0.102.1 and 0.102.0 could allow an unauthentica

Version: 0.102.1+dfsg-0ubuntu0.18.04.2 2020-01-08 15:06:21 UTC

  clamav (0.102.1+dfsg-0ubuntu0.18.04.2) bionic-security; urgency=medium

  * Updated to 0.102.1 to fix security issue (CVE-2019-15961)
    - debian/patches/*: synced patches with 0.102.1+dfsg-1ubuntu1.
    - debian/clamav-daemon.*.in,clamav-freshclam.*.in,
      clamav-daemon.templates: added new configuration options, dropped
      ClamOnAccess.
    - debian/clamav-deamon.install: install new clamonacc binary.
    - debian/clamav-docs.*: removed missing docs.
    - debian/libclamav9.install: added libfreshclam.so.2.
    - debian/libclamav9.symbols: updated for new version.
    - debian/rules: bumped CL_FLEVEL to 112.

 -- Marc Deslauriers <email address hidden> Tue, 07 Jan 2020 10:53:05 -0500

Source diff to previous version

Version: 0.101.4+dfsg-0ubuntu0.18.04.1 2019-10-02 12:07:12 UTC

  clamav (0.101.4+dfsg-0ubuntu0.18.04.1) bionic-security; urgency=medium

  * Updated to version 0.101.4 to fix security issues.
    - debian/patches/*: sync patches with 0.101.4+dfsg-1ubuntu1.
    - debian/clamav-daemon.postinst.in: removed DetectBrokenExecutables,
      added MaxScanTime, HeuristicAlerts, Alert*.
    - debian/*: updated for new library version.
    - debian/libclamav9.symbols: updated for new version.
    - debian/clamav-docs*, debian/rules: fix doc file locations.
    - debian/libclam-dev.install: include new header file.
    - CVE-2019-12625
    - CVE-2019-12900

 -- Marc Deslauriers <email address hidden> Tue, 24 Sep 2019 05:31:17 -0400

CVE-2019-12625 clamav zip DoS
CVE-2019-12900 BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.



About   -   Send Feedback to @ubuntu_updates