MGASA-2014-0487

Source
https://advisories.mageia.org/MGASA-2014-0487.html
Import Source
https://advisories.mageia.org/MGASA-2014-0487.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0487
Related
Published
2014-11-26T10:14:01Z
Modified
2014-11-26T10:00:38Z
Summary
Updated clamav packages fix security vulnerabilities
Details

Certain javascript files causes ClamAV to segfault when scanned with the -a (list archived files) (CVE-2013-6497).

A heap buffer overflow was reported in ClamAV when scanning a specially crafted y0da Crypter obfuscated PE file (CVE-2014-9050).

ClamAV has been updated to version 0.98.5 to address these and other issues.

References
Credits

Affected packages

Mageia:4 / clamav

Package

Name
clamav
Purl
pkg:rpm/mageia/clamav?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.98.5-1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:3 / clamav

Package

Name
clamav
Purl
pkg:rpm/mageia/clamav?distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.98.5-1.mga3

Ecosystem specific

{
    "section": "core"
}