Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

SUSE: 2015:0298-1 Important: ClamAV DoS And Heap Exploit Fixes

suse
Calendar Grey February 17, 2015
Dist Suse Esm H88
SUSE announces a significant upgrade for clamav addressing four major vulnerabilities affecting various corporate distributions.
An update that fixes four vulnerabilities is now available

Summary

clamav was updated to version 0.98.6 to fix four security issues. These security issues have been fixed: * CVE-2015-1462: ClamAV allowed remote attackers to have unspecified impact via a crafted upx packer file, related to a heap out of bounds condition (bnc#916214). * CVE-2015-1463: ClamAV allowed remote attackers to cause a denial of service (crash) via a crafted petite packer file, related to an incorrect compiler optimization (bnc#916215). * CVE-2014-9328: ClamAV allowed remote attackers to have unspecified impact via a crafted upack packer file, related to a heap out of bounds condition (bnc#915512). * CVE-2015-1461: ClamAV allowed remote attackers to have unspecified impact via a crafted (1) Yoda's crypter or (2) mew packer file, related to a heap out of bounds condition (bnc#916217). Security Issues:

References

#915512 #916214 #916215 #916217

Cross- CVE-2014-9328 CVE-2015-1461 CVE-2015-1462

CVE-2015-1463

Affected Products:

SUSE Linux Enterprise Server 11 SP3 for VMware

SUSE Linux Enterprise Server 11 SP3

SUSE Linux Enterprise Server 11 SP2 LTSS

SUSE Linux Enterprise Server 11 SP1 LTSS

SUSE Linux Enterprise Server 10 SP4 LTSS

SUSE Linux Enterprise Desktop 11 SP3

https://www.suse.com/security/cve/CVE-2014-9328.html

https://www.suse.com/security/cve/CVE-2015-1461.html

https://www.suse.com/security/cve/CVE-2015-1462.html

https://www.suse.com/security/cve/CVE-2015-1463.html

https://bugzilla.suse.com/show_bug.cgi?id=915512

https://bugzilla.suse.com/show_bug.cgi?id=916214

https://bugzilla.suse.com/show_bug.cgi?id=916215

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:0298-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here