Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Ubuntu 16.04 and 14.04 ESM: USN-5233-2 Critical ClamAV Crash

Ubuntu Large Esm H500
ClamAV could be made to crash if it opened a specially crafted file.
=========================================================================Ubuntu Security Notice USN-5233-2
January 19, 2022

clamav vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 ESM
- Ubuntu 14.04 ESM

Summary:

ClamAV could be made to crash if it opened a specially crafted file.

Software Description:
- clamav: Anti-virus utility for Unix

Details:

USN-5233-1 fixed a vulnerability in ClamAV. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.

Original advisory details:

 It was discovered that ClamAV incorrectly handled memory when the
 CL_SCAN_GENERAL_COLLECT_METADATA scan option was enabled. A remote attacker
 could possibly use this issue to cause ClamAV to crash, resulting in a
 denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 ESM:
  clamav                          0.103.5+dfsg-0ubuntu0.16.04.1+esm1

Ubuntu 14.04 ESM:
  clamav                          0.103.5+dfsg-0ubuntu0.14.04.1+esm1

This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.

References:
  https://ubuntu.com/security/notices/USN-5233-2
  https://ubuntu.com/security/notices/USN-5233-1
  CVE-2022-20698

Ubuntu 16.04 and 14.04 ESM: USN-5233-2 Critical ClamAV Crash

ubuntu
Calendar Grey January 19, 2022
Dist Ubuntu Esm H88
Enhance ClamAV on Ubuntu platforms in response to a severe crash flaw, impacting editions 14.04 and 16.04 ESM.
ClamAV could be made to crash if it opened a specially crafted file.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: clamav 0.103.5+dfsg-0ubuntu0.16.04.1+esm1 Ubuntu 14.04 ESM: clamav 0.103.5+dfsg-0ubuntu0.14.04.1+esm1 This update uses a new upstream release, which includes additional bug fixes. In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5233-2

https://ubuntu.com/security/notices/USN-5233-1

CVE-2022-20698

Severity
critical
Lowest
Low
Medium
High
Critical

January 19, 2022

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here