This update for clamav fixes the following issues:
New version 1.4.2:
* CVE-2025-20128, bsc#1236307: Fixed a possible buffer overflow read bug in
the OLE2 file parser that could cause a denial-of-service (DoS) condition.
* Start clamonacc with --fdpass to avoid errors due to clamd not being able to
access user files. (bsc#1232242)
* New version 1.4.1:
* https://blog.clamav.net/2024/09/clamav-141-132-107-and-010312-security.html
* New version 1.4.0:
* Added support for extracting ALZ archives.
* Added support for extracting LHA/LZH archives.
* Added the ability to disable image fuzzy hashing, if needed. For context,
image fuzzy hashing is a detection mechanism useful for identifying malware
by matching images included with the malware or phishing email/document.
* https://blog.clamav.net/2024/08/clamav-140-feature-release-and-clamav.html
* New version 1.3.2:
* CVE-2024-20506: Changed the logging module to disable following symlinks on
...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.6
zypper in -t patch SUSE-2025-327=1 openSUSE-SLE-15.6-2025-327=1
* Basesystem Module 15-SP6
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-327=1
* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586)
* clamav-1.4.2-150600.18.6.1
* libfreshclam3-debuginfo-1.4.2-150600.18.6.1
* libclamav12-1.4.2-150600.18.6.1
* clamav-devel-1.4.2-150600.18.6.1
* libclammspack0-debuginfo-1.4.2-150600.18.6.1
* clamav-debuginfo-1.4.2-150600.18.6.1
* libfreshclam3-1.4.2-150600.18.6.1
* libclamav12-debuginfo-1.4.2-150600.18.6.1
* clamav-debugsource-1.4.2-150600.18.6.1
* libclammspack0-1.4.2-150600.18.6.1
* clamav-milter-debuginfo-1.4.2-150600.18.6.1
* clamav-milter-1.4.2-150600.18.6.1
* openSUSE Leap 15.6 (noarch)
* clamav-docs-html-1.4.2-150600.18.6.1
* Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64)
* clamav-1.4.2-150600.18.6.1
* libfreshclam3-debuginfo-1.4.2-150600.18.6.1
* libclamav12-1.4.2-150600.18.6.1
* clamav-devel-1.4.2-150600.18.6.1
* libclammspack0-debuginfo-1.4.2-150600.18.6.1
* clamav-debuginfo-1.4.2-150600.18.6.1
* libfreshclam3-1.4.2-150600.18.6.1
* libclamav12-debuginfo-1.4.2-150600.18.6.1
* clamav-debugsource-1.4.2-150600.18.6.1
*...
Read the Full Advisory* bsc#1102840
* bsc#1103032
* bsc#1180296
* bsc#1202986
* bsc#1211594
* bsc#1214342
* bsc#1232242
* bsc#1236307
* jsc#PED-4596
## References:
* https://www.suse.com/security/cve/CVE-2018-14679.html
* https://www.suse.com/security/cve/CVE-2023-20197.html
* https://www.suse.com/security/cve/CVE-2024-20380.html
* https://www.suse.com/security/cve/CVE-2024-20505.html
* https://www.suse.com/security/cve/CVE-2024-20506.html
* https://www.suse.com/security/cve/CVE-2025-20128.html
* https://bugzilla.suse.com/show_bug.cgi?id=1102840
* https://bugzilla.suse.com/show_bug.cgi?id=1103032
* https://bugzilla.suse.com/show_bug.cgi?id=1180296
* https://bugzilla.suse.com/show_bug.cgi?id=1202986
* https://bugzilla.suse.com/show_bug.cgi?id=1211594
* https://bugzilla.suse.com/show_bug.cgi?id=1214342
* https://bugzilla.suse.com/show_bug.cgi?id=1232242
* https://bugzilla.suse.com/show_bug.cgi?id=1236307
* https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FPED-4596&page_caps=&user_role=
Get the latest Linux and open source security news straight to your inbox.