Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

SUSE: 2019:14231-1 Moderate: clamav Zip Bomb & Out-Of-Bounds Issues

suse
Calendar Grey November 26, 2019
Dist Suse Esm H88
Addresses several security flaws in clamav, improving SUSE's protective measures. Detailed installation guidelines are included.
An update that fixes two vulnerabilities is now available

Summary

This update for clamav fixes the following issues: Security issues fixed: - CVE-2019-12625: Fixed a ZIP bomb issue by adding detection and heuristics for zips with overlapping files (bsc#1144504). - CVE-2019-12900: Fixed an out-of-bounds write in decompress.c with many selectors (bsc#1149458). Non-security issue fixed: - Added the --max-scantime clamscan option and MaxScanTime clamd configuration option. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4-LTSS: zypper in -t patch slessp4-clamav-14231=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patch sleposp3-clamav-14231=1

References

#1144504 #1149458

Cross- CVE-2019-12625 CVE-2019-12900

Affected Products:

SUSE Linux Enterprise Server 11-SP4-LTSS

SUSE Linux Enterprise Point of Sale 11-SP3

SUSE Linux Enterprise Debuginfo 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP3

https://www.suse.com/security/cve/CVE-2019-12625.html

https://www.suse.com/security/cve/CVE-2019-12900.html

https://bugzilla.suse.com/1144504

https://bugzilla.suse.com/1149458

Announcement ID: SUSE-SU-2019:14231-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here