Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

SUSE: 2018:2230-1 Moderate: Clamav Security Update for Two Issues

suse
Calendar Grey August 7, 2018
Dist Suse Esm H88
SUSE Security Update for nginx resolves multiple vulnerabilities and includes crucial setup guidelines.
An update that solves two vulnerabilities and has two fixes is now available

Summary

This update for clamav to version 0.100.1 fixes the following issues: The following security vulnerabilities were addressed: - CVE-2018-0360: HWP integer overflow, infinite loop vulnerability (bsc#1101410) - CVE-2018-0361: PDF object length check, unreasonably long time to parse relatively small file (bsc#1101412) - Buffer over-read in unRAR code due to missing max value checks in table initialization - Libmspack heap buffer over-read in CHM parser (bsc#1103040) - PDF parser bugs The following other changes were made: - Disable YARA support for licensing reasons (bsc#1101654). - Add HTTPS support for clamsubmit - Fix for DNS resolution for users on IPv4-only machines where IPv6 is not available or is link-local only Patch Instructions:

References

#1101410 #1101412 #1101654 #1103040

Cross- CVE-2018-0360 CVE-2018-0361

Affected Products:

SUSE Linux Enterprise Module for Basesystem 15

https://www.suse.com/security/cve/CVE-2018-0360.html

https://www.suse.com/security/cve/CVE-2018-0361.html

https://bugzilla.suse.com/1101410

https://bugzilla.suse.com/1101412

https://bugzilla.suse.com/1101654

https://bugzilla.suse.com/1103040

Announcement ID: SUSE-SU-2018:2230-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here