Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

openSUSE 42.3: 2018:0258-1 important: clamav denial of service

opensuse
Calendar Grey January 28, 2018
Dist Opensuse Esm H88
The latest ClamAV release resolves 11 security issues within openSUSE, significantly bolstering system integrity and reliability via critical updates.
An update that fixes 11 vulnerabilities is now available.

Description

This update for clamav fixes the following issues:

- Update to security release 0.99.3 (bsc#1077732)

* CVE-2017-12376 (ClamAV Buffer Overflow in handle_pdfname Vulnerability)

* CVE-2017-12377 (ClamAV Mew Packet Heap Overflow Vulnerability)

* CVE-2017-12379 (ClamAV Buffer Overflow in messageAddArgument

Vulnerability)

- these vulnerabilities could have allowed an unauthenticated, remote

attacker to cause a denial of service (DoS) condition

or potentially execute arbitrary code on an affected device.

* CVE-2017-12374 (ClamAV use-after-free Vulnerabilities)

* CVE-2017-12375 (ClamAV Buffer Overflow Vulnerability)

* CVE-2017-12378 (ClamAV Buffer Over Read Vulnerability)

* CVE-2017-12380 (ClamAV Null Dereference Vulnerability)

- these vulnerabilities could have allowed an unauthenticated, remote

attacker to cause a denial of service (DoS) condition on an affected

device.

* CVE-2017-6420...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.3:

zypper in -t patch openSUSE-2018-102=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE Leap 42.3 (x86_64):

clamav-0.99.3-20.1

clamav-debuginfo-0.99.3-20.1

clamav-debugsource-0.99.3-20.1

References

https://www.suse.com/security/cve/CVE-2017-11423.html

https://www.suse.com/security/cve/CVE-2017-12374.html

https://www.suse.com/security/cve/CVE-2017-12375.html

https://www.suse.com/security/cve/CVE-2017-12376.html

https://www.suse.com/security/cve/CVE-2017-12377.html

https://www.suse.com/security/cve/CVE-2017-12378.html

https://www.suse.com/security/cve/CVE-2017-12379.html

https://www.suse.com/security/cve/CVE-2017-12380.html

https://www.suse.com/security/cve/CVE-2017-6418.html

https://www.suse.com/security/cve/CVE-2017-6419.html

https://www.suse.com/security/cve/CVE-2017-6420.html

https://bugzilla.suse.com/show_bug.cgi?id=1040662

https://bugzilla.suse.com/1049423

https://bugzilla.suse.com/1052448

https://bugzilla.suse.com/1052449

https://bugzilla.suse.com/show_bug.cgi?id=1052466

https://bugzilla.suse.com/1077732

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2018:0258-1
Rating: important
Affected Products: openSUSE Leap 42.3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here