SUSE Security Update: Security update for clamav
______________________________________________________________________________

Announcement ID:    SUSE-SU-2017:1716-1
Rating:             important
References:         #1040662 #1045490 
Cross-References:   CVE-2012-6706
Affected Products:
                    SUSE Linux Enterprise Server for SAP 12-SP1
                    SUSE Linux Enterprise Server for SAP 12
                    SUSE Linux Enterprise Server for Raspberry Pi 12-SP2
                    SUSE Linux Enterprise Server 12-SP2
                    SUSE Linux Enterprise Server 12-SP1-LTSS
                    SUSE Linux Enterprise Server 12-LTSS
                    SUSE Linux Enterprise Desktop 12-SP2
______________________________________________________________________________

   An update that solves one vulnerability and has one errata
   is now available.

Description:


   This update for clamav fixes the following issues:

   Security issue fixed:

   - CVE-2012-6706: Fixed an arbitrary memory write in VMSF_DELTA filter in
     libclamunrar (bsc#1045490)

   Non security issues fixed:

   - Provide and obsolete clamav-nodb to trigger its removal in openSUSE
     Leap. (bsc#1040662)


Patch Instructions:

   To install this SUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Server for SAP 12-SP1:

      zypper in -t patch SUSE-SLE-SAP-12-SP1-2017-1069=1

   - SUSE Linux Enterprise Server for SAP 12:

      zypper in -t patch SUSE-SLE-SAP-12-2017-1069=1

   - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2:

      zypper in -t patch SUSE-SLE-RPI-12-SP2-2017-1069=1

   - SUSE Linux Enterprise Server 12-SP2:

      zypper in -t patch SUSE-SLE-SERVER-12-SP2-2017-1069=1

   - SUSE Linux Enterprise Server 12-SP1-LTSS:

      zypper in -t patch SUSE-SLE-SERVER-12-SP1-2017-1069=1

   - SUSE Linux Enterprise Server 12-LTSS:

      zypper in -t patch SUSE-SLE-SERVER-12-2017-1069=1

   - SUSE Linux Enterprise Desktop 12-SP2:

      zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-1069=1

   To bring your system up-to-date, use "zypper patch".


Package List:

   - SUSE Linux Enterprise Server for SAP 12-SP1 (ppc64le x86_64):

      clamav-0.99.2-32.1
      clamav-debuginfo-0.99.2-32.1
      clamav-debugsource-0.99.2-32.1

   - SUSE Linux Enterprise Server for SAP 12 (x86_64):

      clamav-0.99.2-32.1
      clamav-debuginfo-0.99.2-32.1
      clamav-debugsource-0.99.2-32.1

   - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (aarch64):

      clamav-0.99.2-32.1
      clamav-debuginfo-0.99.2-32.1
      clamav-debugsource-0.99.2-32.1

   - SUSE Linux Enterprise Server 12-SP2 (aarch64 ppc64le x86_64):

      clamav-0.99.2-32.1
      clamav-debuginfo-0.99.2-32.1
      clamav-debugsource-0.99.2-32.1

   - SUSE Linux Enterprise Server 12-SP1-LTSS (ppc64le s390x x86_64):

      clamav-0.99.2-32.1
      clamav-debuginfo-0.99.2-32.1
      clamav-debugsource-0.99.2-32.1

   - SUSE Linux Enterprise Server 12-LTSS (ppc64le s390x x86_64):

      clamav-0.99.2-32.1
      clamav-debuginfo-0.99.2-32.1
      clamav-debugsource-0.99.2-32.1

   - SUSE Linux Enterprise Desktop 12-SP2 (x86_64):

      clamav-0.99.2-32.1
      clamav-debuginfo-0.99.2-32.1
      clamav-debugsource-0.99.2-32.1


References:

   https://www.suse.com/security/cve/CVE-2012-6706.html
   https://bugzilla.suse.com/1040662
   https://bugzilla.suse.com/1045490

SuSE: 2017:1716-1: important: clamav

June 29, 2017
An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is ...

Summary

This update for clamav fixes the following issues: Security issue fixed: - CVE-2012-6706: Fixed an arbitrary memory write in VMSF_DELTA filter in libclamunrar (bsc#1045490) Non security issues fixed: - Provide and obsolete clamav-nodb to trigger its removal in openSUSE Leap. (bsc#1040662) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2017-1069=1 - SUSE Linux Enterprise Server for SAP 12: zypper in -t patch SUSE-SLE-SAP-12-2017-1069=1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2: zypper in -t patch SUSE-SLE-RPI-12-SP2-2017-1069=1 - SUSE Linux Enterprise Server 12-SP2: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2017-1069=1 - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2017-1069=1 - SUSE Linux Enterprise Server 12-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-2017-1069=1 - SUSE Linux Enterprise Desktop 12-SP2: zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-1069=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server for SAP 12-SP1 (ppc64le x86_64): clamav-0.99.2-32.1 clamav-debuginfo-0.99.2-32.1 clamav-debugsource-0.99.2-32.1 - SUSE Linux Enterprise Server for SAP 12 (x86_64): clamav-0.99.2-32.1 clamav-debuginfo-0.99.2-32.1 clamav-debugsource-0.99.2-32.1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (aarch64): clamav-0.99.2-32.1 clamav-debuginfo-0.99.2-32.1 clamav-debugsource-0.99.2-32.1 - SUSE Linux Enterprise Server 12-SP2 (aarch64 ppc64le x86_64): clamav-0.99.2-32.1 clamav-debuginfo-0.99.2-32.1 clamav-debugsource-0.99.2-32.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (ppc64le s390x x86_64): clamav-0.99.2-32.1 clamav-debuginfo-0.99.2-32.1 clamav-debugsource-0.99.2-32.1 - SUSE Linux Enterprise Server 12-LTSS (ppc64le s390x x86_64): clamav-0.99.2-32.1 clamav-debuginfo-0.99.2-32.1 clamav-debugsource-0.99.2-32.1 - SUSE Linux Enterprise Desktop 12-SP2 (x86_64): clamav-0.99.2-32.1 clamav-debuginfo-0.99.2-32.1 clamav-debugsource-0.99.2-32.1

References

#1040662 #1045490

Cross- CVE-2012-6706

Affected Products:

SUSE Linux Enterprise Server for SAP 12-SP1

SUSE Linux Enterprise Server for SAP 12

SUSE Linux Enterprise Server for Raspberry Pi 12-SP2

SUSE Linux Enterprise Server 12-SP2

SUSE Linux Enterprise Server 12-SP1-LTSS

SUSE Linux Enterprise Server 12-LTSS

SUSE Linux Enterprise Desktop 12-SP2

https://www.suse.com/security/cve/CVE-2012-6706.html

https://bugzilla.suse.com/1040662

https://bugzilla.suse.com/1045490

Severity
Announcement ID: SUSE-SU-2017:1716-1
Rating: important

Related News