Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2020:3790-1 Moderate: clamav Denial of Service Update Fix

suse
Calendar Grey December 14, 2020
Dist Suse Esm H88
SUSE has rolled out a security update addressing various vulnerabilities in clamav classified as moderate risk. Please verify that your systems are up to date.
An update that fixes 14 vulnerabilities, contains one feature is now available

Summary

This update for clamav fixes the following issues: clamav was updated to the new major release 0.103.0. (jsc#ECO-3010,bsc#1118459) Note that libclamav was changed incompatible, if you have a 3rd party application that uses libclamav, it needs to be rebuilt. Update to 0.103.0 * clamd can now reload the signature database without blocking scanning. This multi-threaded database reload improvement was made possible thanks to a community effort. - Non-blocking database reloads are now the default behavior. Some systems that are more constrained on RAM may need to disable non-blocking reloads as it will temporarily consume two times as much memory. We added a new clamd config option ConcurrentDatabaseReload, which may be set to no. * Fix clamav-milter.service (requires clamd.service to run) Update to 0.102.4

References

#1104457 #1118459 #1130721 #1144504 #1149458

#1157763 ECO-3010

Cross- CVE-2019-12625 CVE-2019-12900 CVE-2019-15961

CVE-2019-1785 CVE-2019-1786 CVE-2019-1787

CVE-2019-1788 CVE-2019-1789 CVE-2019-1798

CVE-2020-3123 CVE-2020-3327 CVE-2020-3341

CVE-2020-3350 CVE-2020-3481

Affected Products:

SUSE Linux Enterprise Module for Basesystem 15-SP2

SUSE Linux Enterprise Module for Basesystem 15-SP1

https://www.suse.com/security/cve/CVE-2019-12625.html

https://www.suse.com/security/cve/CVE-2019-12900.html

https://www.suse.com/security/cve/CVE-2019-15961.html

https://www.suse.com/security/cve/CVE-2019-1785.html

https://www.suse.com/security/cve/CVE-2019-1786.html

https://www.suse.com/security/cve/CVE-2019-1787.html

Announcement ID: SUSE-SU-2020:3790-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here