#1011746 bullseye-pu: package clamav/0.103.6+dfsg-0+deb11u1

#1011746#5
Date:
2022-05-26 08:47:52 UTC
From:
To:
This is an long overdue update to the clamav package. It is a stable
update provided by upstream closing CVEs bugs:
- CVE-2022-20770 (Possible infinite loop vulnerability in the CHM file
  parser).
- CVE-2022-20796 (Possible NULL-pointer dereference crash in the scan
  verdict cache check).
- CVE-2022-20771 (Possible infinite loop vulnerability in the TIFF file
  parser).
- CVE-2022-20785 (Possible memory leak in the HTML file parser/
  Javascript normalizer).
- CVE-2022-20792 (Possible multi-byte heap buffer overflow write
  vulnerability in the signature database load module.

Please find attached the debdiff.
The upload to unstable occurred on 12th May. I'm not aware of any
regressions.
I have the Buster version running on my machine since this morning. I'm
confident and don't expect any surprises.

Sebastian

#1011746#10
Date:
2022-05-26 19:22:16 UTC
From:
To:
package release.debian.org
tags 1011746 = bullseye pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye.

Thanks for your contribution!

Upload details
==============

Package: clamav
Version: 0.103.6+dfsg-0+deb11u1

Explanation: new upstream stable release; security fixes [CVE-2022-20770 CVE-2022-20771 CVE-2022-20785 CVE-2022-20792 CVE-2022-20796]

#1011746#15
Date:
2022-05-26 19:22:16 UTC
From:
To:
package release.debian.org
tags 1011746 = bullseye pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye.

Thanks for your contribution!

Upload details
==============

Package: clamav
Version: 0.103.6+dfsg-0+deb11u1

Explanation: new upstream stable release; security fixes [CVE-2022-20770 CVE-2022-20771 CVE-2022-20785 CVE-2022-20792 CVE-2022-20796]

#1011746#20
Date:
2022-07-09 10:47:43 UTC
From:
To:
(re-sending with fixed bug numbers)

Hi,

The updates discussed in these bugs were included in today's bullseye
point release.

Regards,

Adam