Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

SUSE: 2014:1571-1 Important: Clamav Buffer Overflow Threats

suse
Calendar Grey December 5, 2014
Scroller Suse
SUSE Security Announcement for clamav addresses critical vulnerabilities impacting your setups and offers guidance for upgrades.
An update that solves two vulnerabilities and has four An update that solves two vulnerabilities and has four An update that solves two vulnerabilities and has four fixes is now av...

Summary

clamav was updated to version 0.98.5 to fix five security issues: * Crash when scanning maliciously crafted yoda's crypter files (CVE-2013-6497). * Heap-based buffer overflow when scanning crypted PE files (CVE-2014-9050). * Fix heap corruption (CVE-2013-2020). * Fix overflow due to PDF key length computation (CVE-2013-2021). * Crash when using 'clamscan -a'. Several non-security issues have also been fixed, please refer to the package's change log for details. Security Issues: * CVE-2013-6497 * CVE-2014-9050 * CVE-2013-2021 * CVE-2013-2020

References

#899395 #903489 #903719 #904207 #906077 #906770

Cross- CVE-2013-6497 CVE-2014-9050

Affected Products:

SUSE Linux Enterprise Server 11 SP2 LTSS

SUSE Linux Enterprise Server 11 SP1 LTSS

https://www.suse.com/security/cve/CVE-2013-6497.html

https://www.suse.com/security/cve/CVE-2014-9050.html

https://bugzilla.suse.com/show_bug.cgi?id=899395

https://bugzilla.suse.com/show_bug.cgi?id=903489

https://bugzilla.suse.com/show_bug.cgi?id=903719

https://bugzilla.suse.com/show_bug.cgi?id=904207

https://bugzilla.suse.com/show_bug.cgi?id=906077

https://bugzilla.suse.com/show_bug.cgi?id=906770

https://scc.suse.com:443/patches/

https://scc.suse.com:443/patches/

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:1571-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.