Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

SUSE Linux Enterprise: 2014:1574-1 Critical: Clamav Buffer Overflow Fix

suse
Calendar Grey December 5, 2014
Scroller Suse
SUSE has released a security patch for clamav, addressing significant vulnerabilities and improving both security and performance across various distributions.
An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three fixes is now...

Summary

clamav was updated to version 0.98.5 to fix three security issues and several non-security issues. These security issues have been fixed: * Crash when scanning maliciously crafted yoda's crypter files (CVE-2013-6497). * Heap-based buffer overflow when scanning crypted PE files (CVE-2014-9050). * Crash when using 'clamscan -a'. These non-security issues have been fixed: * Support for the XDP file format and extracting, decoding, and scanning PDF files within XDP files. * Addition of shared library support for LLVM versions 3.1 - 3.5 for the purpose of just-in-time(JIT) compilation of ClamAV bytecode signatures. * Enhancements to the clambc command line utility to assist ClamAV bytecode signature authors by providing introspection into compiled bytecode programs.

References

#903489 #903719 #904207 #906077 #906770

Cross- CVE-2013-6497 CVE-2014-9050

Affected Products:

SUSE Linux Enterprise Server 11 SP3 for VMware

SUSE Linux Enterprise Server 11 SP3

SUSE Linux Enterprise Server 10 SP4 LTSS

SUSE Linux Enterprise Desktop 11 SP3

https://www.suse.com/security/cve/CVE-2013-6497.html

https://www.suse.com/security/cve/CVE-2014-9050.html

https://bugzilla.suse.com/show_bug.cgi?id=903489

https://bugzilla.suse.com/show_bug.cgi?id=903719

https://bugzilla.suse.com/show_bug.cgi?id=904207

https://bugzilla.suse.com/show_bug.cgi?id=906077

https://bugzilla.suse.com/show_bug.cgi?id=906770

https://scc.suse.com:443/patches/

https://scc.suse.com:443/patches/

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:1574-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.