MGASA-2015-0056

Source
https://advisories.mageia.org/MGASA-2015-0056.html
Import Source
https://advisories.mageia.org/MGASA-2015-0056.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2015-0056
Related
Published
2015-02-09T21:44:14Z
Modified
2015-02-09T21:35:32Z
Summary
Updated clamav packages fix security vulnerabilities
Details

ClamAV 0.98.6 is a maintenance release to fix some bugs, some of them being security bugs:

Fix a heap out of bounds condition with crafted Yoda's crypter files. This issue was discovered by Felix Groebert of the Google Security Team.

Fix a heap out of bounds condition with crafted mew packer files. This issue was discovered by Felix Groebert of the Google Security Team.

Fix a heap out of bounds condition with crafted upx packer files. This issue was discovered by Kevin Szkudlapski of Quarkslab.

Fix a heap out of bounds condition with crafted upack packer files. This issue was discovered by Sebastian Andrzej Siewior (CVE-2014-9328).

Compensate a crash due to incorrect compiler optimization when handling crafted petite packer files. This issue was discovered by Sebastian Andrzej Siewior.

References
Credits

Affected packages

Mageia:4 / clamav

Package

Name
clamav
Purl
pkg:rpm/mageia/clamav?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.98.6-1.mga4

Ecosystem specific

{
    "section": "core"
}