Several security issues were fixed in libclamunrar.. ========================================================================== Ubuntu Security Notice USN-6569-1 January 08, 2024 libclamunrar vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.10 - Ubuntu 23.04 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in libclamunrar. Software Description: - libclamunrar: anti-virus utility for Unix - unrar support Details: it was discovered that libclamunrar incorrectly handled directories when extracting RAR archives. A remote attacker could possibly use this issue to overwrite arbitrary files and execute arbitrary code. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 23.04. (CVE-2022-30333) It was discovered that libclamunrar incorrectly validated certain structures when extracting RAR archives. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2023-40477) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.10: libclamunrar11 1.0.4-0ubuntu0.23.10.1 Ubuntu 23.04: libclamunrar9 0.103.11-0ubuntu0.23.04.1 Ubuntu 22.04 LTS: libclamunrar9 0.103.11-0ubuntu0.22.04.1 Ubuntu 20.04 LTS: libclamunrar9 0.103.11-0ubuntu0.20.04.1 This update uses a new upstream release, which includes additional bug fixes. In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6569-1 CVE-2022-30333, CVE-2023-40477 Package Information: https://launchpad.net/ubuntu/+source/libclamunrar/1.0.4-0ubuntu0.23.10.1 https://launchpad.net/ubuntu/+source/libclamunrar/0.103.11-0ubuntu0.23.04.1 https://launchpad.net/ubuntu/+source/libclamunrar/0.103.11-0ubuntu0.22.04.1 https://launchpad.net/ubuntu/+source/libclamunrar/0.103.11-0ubuntu0.20.04.1 . Critical flaws in libclamunrar have been addressed in Ubuntu updates, significantly diminishing the chances of remote exploitation.. Libclamunrar Security Update, Ubuntu Security Notice, Remote Code Execution. . Severity: Critical. LinuxSecurity.com Team
A buffer overflow was found in the RAR code used by libclamunrar, which could result in arbitrary code execution when processing malicious RAR archives. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3653-1
* bsc#1216625 Cross-References: * CVE-2023-40477 . # Security update for clamav Announcement ID: SUSE-SU-2023:4297-1 Rating: important References: * bsc#1216625 Cross-References: * CVE-2023-40477 CVSS scores: Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for clamav fixes the following issues: * Updated to version 0.103.11: * CVE-2023-40477: Updated libclamunrar dependency to version 6.2.12 (bsc#1216625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2023-4297=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2023-4297=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2023-4297=1 ## Package List: * SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 x86_64) * clamav-debugsource-0.103.11-3.30.1 * clamav-0.103.11-3.30.1 * clamav-debuginfo-0.103.11-3.30.1 * SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64) * clamav-debugsource-0.103.11-3.30.1 * clamav-0.103.11-3.30.1 * clamav-debuginfo-0.103.11-3.30.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * clamav-debugsource-0.103.11-3.30.1 * clamav-0.103.11-3.30.1 * clamav-debuginfo-0.103.11-3.30.1 ## References: * https://www.suse.com/security/cve/CVE-2023-40477.html * https://bugzilla.suse.com/show_bug.cgi?id=1216625 . Crucial safety patch for clamav addressing CVE-2023-40477 in SUSE systems is now accessible.. clamav update,SUSE security advisory, SUSE Linux Enterprise. . Severity: Important. LinuxSecurity.com Team
It was discovered that there was an arbitrary code execution vulnerability in libcamunrar, a library to add unrar support to the Clam anti-virus software. This was caused by an integer overflow resulting in a negative value of the . Hash: SHA256 Package : libclamunrar Version : 0.99-0+deb7u2 CVE ID : CVE-2017-7520 Debian Bug : #867223 It was discovered that there was an arbitrary code execution vulnerability in libcamunrar, a library to add unrar support to the Clam anti-virus software. This was caused by an integer overflow resulting in a negative value of the ``DestPos`` variable, which allows the attacker to write out of bounds when setting ``Mem[DestPos]``. For Debian 7 "Wheezy", this issue has been fixed in libclamunrar version 0.99-0+deb7u2. We recommend that you upgrade your libclamunrar packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'`
Get the latest Linux and open source security news straight to your inbox.