Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

SUSE: 2018:2323-1 Moderate: Clamav Buffer Over-Read Issues

suse
Calendar Grey August 14, 2018
Dist Suse Esm H88
SUSE Security Update for openssl addresses vulnerabilities in various software, including memory corruption and denial of service.
An update that solves four vulnerabilities and has one errata is now available

Summary

This update for clamav to version 0.100.1 fixes the following issues: The following security vulnerabilities were addressed: - CVE-2018-0360: HWP integer overflow, infinite loop vulnerability (bsc#1101410) - CVE-2018-0361: PDF object length check, unreasonably long time to parse relatively small file (bsc#1101412) - CVE-2018-1000085: Fixed a out-of-bounds heap read in XAR parser (bsc#1082858) - CVE-2018-14679: Libmspack heap buffer over-read in CHM parser (bsc#1103040) - Buffer over-read in unRAR code due to missing max value checks in table initialization - PDF parser bugs The following other changes were made: - Disable YARA support for licensing reasons (bsc#1101654). - Add HTTPS support for clamsubmit - Fix for DNS resolution for users on IPv4-only machines where IPv6 is not

References

#1082858 #1101410 #1101412 #1101654 #1103040

Cross- CVE-2018-0360 CVE-2018-0361 CVE-2018-1000085

CVE-2018-14679

Affected Products:

SUSE OpenStack Cloud 7

SUSE Linux Enterprise Server for SAP 12-SP2

SUSE Linux Enterprise Server for SAP 12-SP1

SUSE Linux Enterprise Server 12-SP3

SUSE Linux Enterprise Server 12-SP2-LTSS

SUSE Linux Enterprise Server 12-SP1-LTSS

SUSE Linux Enterprise Server 12-LTSS

SUSE Linux Enterprise Desktop 12-SP3

SUSE Enterprise Storage 4

https://www.suse.com/security/cve/CVE-2018-0360.html

https://www.suse.com/security/cve/CVE-2018-0361.html

https://www.suse.com/security/cve/CVE-2018-1000085.html

https://www.suse.com/security/cve/CVE-2018-14679.html

https://bugzilla.suse.com/1082858

https://bugzilla.suse.com/1101410

Announcement ID: SUSE-SU-2018:2323-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here