Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Mageia 8 MGASA-2023-0068: ClamAV Remote Execution And Leak Issues

mageia
Calendar Grey February 27, 2023
Dist Mageia Esm H88
The security update for ClamAV addresses vulnerabilities related to code execution and data leakage. For more information, refer to advisory MGASA-2023-0068.
A possible remote code execution vulnerability in the HFS+ file parser

Summary

A possible remote code execution vulnerability in the HFS+ file parser. (CVE-2023-20032)
A possible remote information leak vulnerability in the DMG file parser. (CVE-2023-20052)

References

- https://bugs.mageia.org/show_bug.cgi?id=31562

- https://blog.clamav.net/2023/02/clamav-01038-01052-and-101-patch.html

- https://www.cve.org/CVERecord?id=CVE-2023-20032

- https://www.cve.org/CVERecord?id=CVE-2023-20052

Resolution

SRPMS

- 8/core/clamav-0.103.8-1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 27 Feb 2023
URL: https://advisories.mageia.org/MGASA-2023-0068.html
Type: security
CVE: CVE-2023-20032, CVE-2023-20052

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here