- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- Sebastian Andrzej Siewior
- Date:
- 2022-07-09 10:52:43 UTC
- Severity:
- normal
- Tags:
This is an long overdue update to the clamav package. It is a stable update provided by upstream closing CVEs bugs: - CVE-2022-20770 (Possible infinite loop vulnerability in the CHM file parser). - CVE-2022-20796 (Possible NULL-pointer dereference crash in the scan verdict cache check). - CVE-2022-20771 (Possible infinite loop vulnerability in the TIFF file parser). - CVE-2022-20785 (Possible memory leak in the HTML file parser/ Javascript normalizer). - CVE-2022-20792 (Possible multi-byte heap buffer overflow write vulnerability in the signature database load module. Please find attached the debdiff. The upload to unstable occurred on 12th May. I'm not aware of any regressions. I have the Buster version running on my machine since this morning. I'm confident and don't expect any surprises. Sebastian
package release.debian.org tags 1011746 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details ============== Package: clamav Version: 0.103.6+dfsg-0+deb11u1 Explanation: new upstream stable release; security fixes [CVE-2022-20770 CVE-2022-20771 CVE-2022-20785 CVE-2022-20792 CVE-2022-20796]
package release.debian.org tags 1011746 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details ============== Package: clamav Version: 0.103.6+dfsg-0+deb11u1 Explanation: new upstream stable release; security fixes [CVE-2022-20770 CVE-2022-20771 CVE-2022-20785 CVE-2022-20792 CVE-2022-20796]
(re-sending with fixed bug numbers) Hi, The updates discussed in these bugs were included in today's bullseye point release. Regards, Adam