Update to yara-4.2.3 ---- Update to 4.2.0 ---- Update to 4.2.2. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-21cf5402fc 2022-08-17 01:05:09.336585 --------------------------------------------------------------------------------Name : yara Product : Fedora 36 Version : 4.2.3 Release : 1.fc36 URL : https://virustotal.github.io/yara/ Summary : Pattern matching Swiss knife for malware researchers Description : YARA is a tool aimed at (but not limited to) helping malware researchers to identify and classify malware samples. With YARA you can create descriptions of malware families (or whatever you want to describe) based on textual or binary patterns. Each description, a.k.a rule, consists of a set of strings and a Boolean expression which determine its logic. --------------------------------------------------------------------------------Update Information: Update to yara-4.2.3 ---- Update to 4.2.0 ---- Update to 4.2.2 --------------------------------------------------------------------------------ChangeLog: * Tue Aug 9 2022 Mikel Olasagasti Uranga - 4.2.3-1 - Update to 4.2.3 (#2116594) * Sat Jul 23 2022 Fedora Release Engineering - 4.2.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild * Mon Jul 18 2022 Mikel Olasagasti Uranga - 4.2.2-1 - Update to 4.2.2 (#2103444) - BUGFIX: Fix buffer overrun in "dex" module (#1728). - BUGFIX: Wrong offset used when checking Version string of .net metadata (#1708). - BUGFIX: YARA doesn't compile if --with-debug-verbose flag is enabled (#1719). - BUGFIX: Null-pointer dereferences while loading corrupted compiled rules (#1727). * Mon May 23 2022 Michal Ambroz - 4.2.1-1 - bump to 4.2.1 - adding changes based on proposal of Mikel Olasagasti Uranga: - change to BSD license as yara was relicensed in 2016 - minor changes to spec, like using https for URL - remove old patches - enable checks * Sat Mar 12 2022Michal Ambroz - 4.2.0-1 - bump to 4.2.0 * Thu Feb 17 2022 Michal Ambroz - 4.2.0-0.rc1.1 - bump to 4.2.0-rc1 --------------------------------------------------------------------------------References: [ 1 ] Bug #2112508 - Update yara to 4.2.2 https://bugzilla.redhat.com/show_bug.cgi?id=2112508 [ 2 ] Bug #2116289 - F36FailsToInstall: python3-yara https://bugzilla.redhat.com/show_bug.cgi?id=2116289 [ 3 ] Bug #2116594 - yara-4.2.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2116594 [ 4 ] Bug #2117081 - F36FailsToInstall: python3-yara https://bugzilla.redhat.com/show_bug.cgi?id=2117081 [ 5 ] Bug #2117161 - python-yara-4.2.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2117161 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-21cf5402fc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update to bugfix release 4.1.0 Security fix for CVE-2017-9438, CVE-2021-3402, CVE-2019-19648, CVE-2017-9438. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-dd62918333 2021-05-06 00:52:28.374770 --------------------------------------------------------------------------------Name : yara Product : Fedora 33 Version : 4.1.0 Release : 1.fc33 URL : https://virustotal.github.io/yara/ Summary : Pattern matching Swiss knife for malware researchers Description : YARA is a tool aimed at (but not limited to) helping malware researchers to identify and classify malware samples. With YARA you can create descriptions of malware families (or whatever you want to describe) based on textual or binary patterns. Each description, a.k.a rule, consists of a set of strings and a Boolean expression which determine its logic. --------------------------------------------------------------------------------Update Information: Update to bugfix release 4.1.0 Security fix for CVE-2017-9438, CVE-2021-3402, CVE-2019-19648, CVE-2017-9438 --------------------------------------------------------------------------------ChangeLog: * Mon Apr 26 2021 Michal Ambroz - 4.1.0-1 - bump to 4.1.0 * Sun Apr 25 2021 Michal Ambroz - 4.0.5-2 - rebuild for epel * Fri Feb 5 2021 Michal Ambroz - 4.0.5-1 - bump to yara bugfix 4.0.5 release * Wed Feb 3 2021 Michal Ambroz - 4.0.4-1 - bump to yara bugfix 4.0.4 release --------------------------------------------------------------------------------References: [ 1 ] Bug #1459012 - CVE-2017-9438 yara: Stack consumption via a crafted rule mishandled in the _ur_re_emit function https://bugzilla.redhat.com/show_bug.cgi?id=1459012 [ 2 ] Bug #1930175 - CVE-2021-3402 libyara: Integer overflow in libyara/modules/macho/macho.c via a malicious Mach-O file https://bugzilla.redhat.com/show_bug.cgi?id=1930175 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-dd62918333' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
update to the bugfix release 3.9.0. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-c3627a0e7a 2019-04-10 02:47:32.732625 --------------------------------------------------------------------------------Name : python-yara Product : Fedora 30 Version : 3.9.0 Release : 2.fc30 URL : https://github.com/VirusTotal/yara-python/ Summary : Python binding for the YARA pattern matching tool Description : Python binding for the YARA pattern matching tool. YARA is a tool aimed at (but not limited to) helping malware researchers to identify and classify malware samples. With YARA you can create descriptions of malware families (or whatever you want to describe) based on textual or binary patterns. Each description, a.k.a rule, consists of a set of strings and a Boolean expression which determine its logic. --------------------------------------------------------------------------------Update Information: update to the bugfix release 3.9.0 --------------------------------------------------------------------------------References: [ 1 ] Bug #1660398 - CVE-2018-19974 CVE-2018-19975 CVE-2018-19976 yara: Multiple issues [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1660398 [ 2 ] Bug #1680203 - yara-3.9.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1680203 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-c3627a0e7a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
bump to 3.6.3 release - bugfix CVE-2017-11328. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-1d46019681 2017-07-24 17:29:46.085217 --------------------------------------------------------------------------------Name : yara Product : Fedora 25 Version : 3.6.3 Release : 1.fc25 URL : https://virustotal.github.io/yara/ Summary : Pattern matching Swiss knife for malware researchers Description : YARA is a tool aimed at (but not limited to) helping malware researchers to identify and classify malware samples. With YARA you can create descriptions of malware families (or whatever you want to describe) based on textual or binary patterns. Each description, a.k.a rule, consists of a set of strings and a Boolean expression which determine its logic. --------------------------------------------------------------------------------Update Information: bump to 3.6.3 release - bugfix CVE-2017-11328 --------------------------------------------------------------------------------References: [ 1 ] Bug #1471490 - yara-3.6.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=1471490 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade yara' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
bump to 3.6.3 release - bugfix CVE-2017-11328. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-944e86b623 2017-07-24 17:26:46.066655 --------------------------------------------------------------------------------Name : yara Product : Fedora 24 Version : 3.6.3 Release : 1.fc24 URL : https://virustotal.github.io/yara/ Summary : Pattern matching Swiss knife for malware researchers Description : YARA is a tool aimed at (but not limited to) helping malware researchers to identify and classify malware samples. With YARA you can create descriptions of malware families (or whatever you want to describe) based on textual or binary patterns. Each description, a.k.a rule, consists of a set of strings and a Boolean expression which determine its logic. --------------------------------------------------------------------------------Update Information: bump to 3.6.3 release - bugfix CVE-2017-11328 --------------------------------------------------------------------------------References: [ 1 ] Bug #1471490 - yara-3.6.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=1471490 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade yara' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
bump to 3.6.3 release - bugfix CVE-2017-11328. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-088b16a69a 2017-07-24 17:28:25.944219 --------------------------------------------------------------------------------Name : yara Product : Fedora 26 Version : 3.6.3 Release : 1.fc26 URL : https://virustotal.github.io/yara/ Summary : Pattern matching Swiss knife for malware researchers Description : YARA is a tool aimed at (but not limited to) helping malware researchers to identify and classify malware samples. With YARA you can create descriptions of malware families (or whatever you want to describe) based on textual or binary patterns. Each description, a.k.a rule, consists of a set of strings and a Boolean expression which determine its logic. --------------------------------------------------------------------------------Update Information: bump to 3.6.3 release - bugfix CVE-2017-11328 --------------------------------------------------------------------------------References: [ 1 ] Bug #1471490 - yara-3.6.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=1471490 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade yara' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Update to a bugfix release of yara.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-926e11c76e 2017-06-17 19:40:29.228745 --------------------------------------------------------------------------------Name : yara Product : Fedora 25 Version : 3.6.0 Release : 1.fc25 URL : https://virustotal.github.io/yara/ Summary : Pattern matching Swiss knife for malware researchers Description : YARA is a tool aimed at (but not limited to) helping malware researchers to identify and classify malware samples. With YARA you can create descriptions of malware families (or whatever you want to describe) based on textual or binary patterns. Each description, a.k.a rule, consists of a set of strings and a Boolean expression which determine its logic. --------------------------------------------------------------------------------Update Information: Update to a bugfix release of yara. --------------------------------------------------------------------------------References: [ 1 ] Bug #1440739 - CVE-2016-10210 CVE-2016-10211 CVE-2017-5923 CVE-2017-5924 yara: Multiple security issues [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1440739 [ 2 ] Bug #1451383 - CVE-2017-8929 yara: Use-after-free in sized_string_cmp function [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451383 [ 3 ] Bug #1451384 - CVE-2017-8929 yara: Use-after-free in sized_string_cmp function [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451384 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade yara' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
ClamAV 0.98.7 This release contains new scanning features and bug fixes. - Improvements to PDF processing: decryption, escape sequence handling, and file property collection. - Scanning/analysis of additional Microsoft Office 2003 XML format.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-7378 2015-05-01 11:30:34 -------------------------------------------------------------------------------- Name : clamav Product : Fedora 20 Version : 0.98.7 Release : 1.fc20 URL : http://www.clamav.net Summary : End-user tools for the Clam Antivirus scanner Description : Clam AntiVirus is an anti-virus toolkit for UNIX. The main purpose of this software is the integration with mail servers (attachment scanning). The package provides a flexible and scalable multi-threaded daemon, a command line scanner, and a tool for automatic updating via Internet. The programs are based on a shared library distributed with the Clam AntiVirus package, which you can use with your own software. The virus database is based on the virus database from OpenAntiVirus, but contains additional signatures (including signatures for popular polymorphic viruses, too) and is KEPT UP TO DATE. -------------------------------------------------------------------------------- Update Information: ClamAV 0.98.7 ============ This release contains new scanning features and bug fixes. - Improvements to PDF processing: decryption, escape sequence handling, and file property collection. - Scanning/analysis of additional Microsoft Office 2003 XML format. - Fix infinite loop condition on crafted y0da cryptor file. Identified and patch suggested by Sebastian Andrzej Siewior. CVE-2015-2221. - Fix crash on crafted petite packed file. Reported and patch supplied by Sebastian Andrzej Siewior. CVE-2015-2222. - Fix false negatives on files within iso9660 containers. This issue was reported by Minzhuan Gong. - Fix a couple crashes on crafted upackpacked file. Identified and patches supplied by Sebastian Andrzej Siewior. - Fix a crash during algorithmic detection on crafted PE file. Identified and patch supplied by Sebastian Andrzej Siewior. - Fix an infinite loop condition on a crafted "xz" archive file. This was reported by Dimitri Kirchner and Goulven Guiheux. CVE-2015-2668. - Fix compilation error after ./configure --disable-pthreads. Reported and fix suggested by John E. Krokes. - Apply upstream patch for possible heap overflow in Henry Spencer's regex library. CVE-2015-2305. - Fix crash in upx decoder with crafted file. Discovered and patch supplied by Sebastian Andrzej Siewior. CVE-2015-2170. - Fix segfault scanning certain HTML files. Reported with sample by Kai Risku. - Improve detections within xar/pkg files. -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 29 2015 Robert Scheck - 0.98.7-1 - Upgrade to 0.98.7 and updated daily.cvd (#1217014) * Tue Mar 10 2015 Adam Jackson 0.98.6-2 - Drop sysvinit subpackages in F23+ * Thu Jan 29 2015 Robert Scheck - 0.98.6-1 - Upgrade to 0.98.6 and updated daily.cvd (#1187050) * Wed Nov 19 2014 Robert Scheck - 0.98.5-2 - Corrected summary of clamav-server-systemd package (#1165672) * Wed Nov 19 2014 Robert Scheck - 0.98.5-1 - Upgrade to 0.98.5 and updated daily.cvd (#1138101) * Sat Aug 16 2014 Fedora Release Engineering - 0.98.4-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild * Sat Jun 21 2014 Robert Scheck - 0.98.4-1 - Upgrade to 0.98.4 and updated daily.cvd (#1111811) - Add build requirement to libxml2 for DMG, OpenIOC and XAR * Sat Jun 7 2014 Fedora Release Engineering - 0.98.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild * Sat May 10 2014 Robert Scheck - 0.98.3-1 - Upgrade to 0.98.3 and updated daily.cvd (#1095614) - Avoid automatic path detection breakage regarding curl - Added build requirement to openssl-devel for hasing code - Added clamsubmit to main package *Wed Jan 15 2014 Robert Scheck - 0.98.1-1 - Upgrade to 0.98.1 and updated daily.cvd (#1053400) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1217207 - CVE-2015-2222 clamav: crash on crafted petite packed file https://bugzilla.redhat.com/show_bug.cgi?id=1217207 [ 2 ] Bug #1217209 - CVE-2015-2170: clamav: Crash in upx decoder with crafted file https://bugzilla.redhat.com/show_bug.cgi?id=1217209 [ 3 ] Bug #1217206 - CVE-2015-2221: clamav Infinite loop condition on crafted y0da cryptor file https://bugzilla.redhat.com/show_bug.cgi?id=1217206 [ 4 ] Bug #1217208 - CVE-2015-2668 clamav: Infinite loop condition on a crafted "xz" archive file https://bugzilla.redhat.com/show_bug.cgi?id=1217208 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update clamav' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.