This update for clamav fixes the following issues: Updated to version 0.103.11:. # Security update for clamav Announcement ID: SUSE-SU-2023:4415-1 Rating: important References: * bsc#1216625 Cross-References: * CVE-2023-40477 CVSS scores: Affected Products: * Basesystem Module 15-SP4 * Basesystem Module 15-SP5 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE CaaS Platform 4.0 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP1 * SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP1 * SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.2 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.2 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.2 * SUSE Manager Server4.3 An update that solves one vulnerability can now be installed. ## Description: This update for clamav fixes the following issues: * Updated to version 0.103.11: * CVE-2023-40477: Updated libclamunrar dependency to version 6.2.12 (bsc#1216625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-4415=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-4415=1 * Basesystem Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2023-4415=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2023-4415=1 * SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2023-4415=1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2023-4415=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-ESPOS-2023-4415=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2023-4415=1 * SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2023-4415=1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2023-4415=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2023-4415=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2023-4415=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2023-4415=1 * SUSE LinuxEnterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2023-4415=1 * SUSE Manager Proxy 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.2-2023-4415=1 * SUSE Manager Retail Branch Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.2-2023-4415=1 * SUSE Manager Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.2-2023-4415=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2023-4415=1 * SUSE CaaS Platform 4.0 To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * clamav-0.103.11-150000.3.50.1 * clamav-debuginfo-0.103.11-150000.3.50.1 * libclamav9-debuginfo-0.103.11-150000.3.50.1 * libfreshclam2-debuginfo-0.103.11-150000.3.50.1 * clamav-debugsource-0.103.11-150000.3.50.1 * libclamav9-0.103.11-150000.3.50.1 * libfreshclam2-0.103.11-150000.3.50.1 * clamav-devel-0.103.11-150000.3.50.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * clamav-0.103.11-150000.3.50.1 * clamav-debuginfo-0.103.11-150000.3.50.1 * libclamav9-debuginfo-0.103.11-150000.3.50.1 * libfreshclam2-debuginfo-0.103.11-150000.3.50.1 * clamav-debugsource-0.103.11-150000.3.50.1 * libclamav9-0.103.11-150000.3.50.1 * libfreshclam2-0.103.11-150000.3.50.1 * clamav-devel-0.103.11-150000.3.50.1 * Basesystem Module 15-SP4 (aarch64 ppc64le s390x x86_64) * clamav-0.103.11-150000.3.50.1 * clamav-debuginfo-0.103.11-150000.3.50.1 * libclamav9-debuginfo-0.103.11-150000.3.50.1 * libfreshclam2-debuginfo-0.103.11-150000.3.50.1 * clamav-debugsource-0.103.11-150000.3.50.1 * libclamav9-0.103.11-150000.3.50.1 * libfreshclam2-0.103.11-150000.3.50.1 * clamav-devel-0.103.11-150000.3.50.1 * BasesystemModule 15-SP5 (aarch64 ppc64le s390x x86_64) * clamav-0.103.11-150000.3.50.1 * clamav-debuginfo-0.103.11-150000.3.50.1 * libclamav9-debuginfo-0.103.11-150000.3.50.1 * libfreshclam2-debuginfo-0.103.11-150000.3.50.1 * clamav-debugsource-0.103.11-150000.3.50.1 * libclamav9-0.103.11-150000.3.50.1 * libfreshclam2-0.103.11-150000.3.50.1 * clamav-devel-0.103.11-150000.3.50.1 * SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 (aarch64 x86_64) * clamav-0.103.11-150000.3.50.1 * clamav-debuginfo-0.103.11-150000.3.50.1 * libclamav9-debuginfo-0.103.11-150000.3.50.1 * libfreshclam2-debuginfo-0.103.11-150000.3.50.1 * clamav-debugsource-0.103.11-150000.3.50.1 * libclamav9-0.103.11-150000.3.50.1 * libfreshclam2-0.103.11-150000.3.50.1 * clamav-devel-0.103.11-150000.3.50.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (aarch64 x86_64) * clamav-0.103.11-150000.3.50.1 * clamav-debuginfo-0.103.11-150000.3.50.1 * libclamav9-debuginfo-0.103.11-150000.3.50.1 * libfreshclam2-debuginfo-0.103.11-150000.3.50.1 * clamav-debugsource-0.103.11-150000.3.50.1 * libclamav9-0.103.11-150000.3.50.1 * libfreshclam2-0.103.11-150000.3.50.1 * clamav-devel-0.103.11-150000.3.50.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 (aarch64 x86_64) * clamav-0.103.11-150000.3.50.1 * clamav-debuginfo-0.103.11-150000.3.50.1 * libclamav9-debuginfo-0.103.11-150000.3.50.1 * libfreshclam2-debuginfo-0.103.11-150000.3.50.1 * clamav-debugsource-0.103.11-150000.3.50.1 * libclamav9-0.103.11-150000.3.50.1 * libfreshclam2-0.103.11-150000.3.50.1 * clamav-devel-0.103.11-150000.3.50.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * clamav-0.103.11-150000.3.50.1 * clamav-debuginfo-0.103.11-150000.3.50.1 * libclamav9-debuginfo-0.103.11-150000.3.50.1 * libfreshclam2-debuginfo-0.103.11-150000.3.50.1 *clamav-debugsource-0.103.11-150000.3.50.1 * libclamav9-0.103.11-150000.3.50.1 * libfreshclam2-0.103.11-150000.3.50.1 * clamav-devel-0.103.11-150000.3.50.1 * SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 (aarch64 ppc64le s390x x86_64) * clamav-0.103.11-150000.3.50.1 * clamav-debuginfo-0.103.11-150000.3.50.1 * libclamav9-debuginfo-0.103.11-150000.3.50.1 * libfreshclam2-debuginfo-0.103.11-150000.3.50.1 * clamav-debugsource-0.103.11-150000.3.50.1 * libclamav9-0.103.11-150000.3.50.1 * libfreshclam2-0.103.11-150000.3.50.1 * clamav-devel-0.103.11-150000.3.50.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (aarch64 ppc64le s390x x86_64) * clamav-0.103.11-150000.3.50.1 * clamav-debuginfo-0.103.11-150000.3.50.1 * libclamav9-debuginfo-0.103.11-150000.3.50.1 * libfreshclam2-debuginfo-0.103.11-150000.3.50.1 * clamav-debugsource-0.103.11-150000.3.50.1 * libclamav9-0.103.11-150000.3.50.1 * libfreshclam2-0.103.11-150000.3.50.1 * clamav-devel-0.103.11-150000.3.50.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (aarch64 ppc64le s390x x86_64) * clamav-0.103.11-150000.3.50.1 * clamav-debuginfo-0.103.11-150000.3.50.1 * libclamav9-debuginfo-0.103.11-150000.3.50.1 * libfreshclam2-debuginfo-0.103.11-150000.3.50.1 * clamav-debugsource-0.103.11-150000.3.50.1 * libclamav9-0.103.11-150000.3.50.1 * libfreshclam2-0.103.11-150000.3.50.1 * clamav-devel-0.103.11-150000.3.50.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 (ppc64le x86_64) * clamav-0.103.11-150000.3.50.1 * clamav-debuginfo-0.103.11-150000.3.50.1 * libclamav9-debuginfo-0.103.11-150000.3.50.1 * libfreshclam2-debuginfo-0.103.11-150000.3.50.1 * clamav-debugsource-0.103.11-150000.3.50.1 * libclamav9-0.103.11-150000.3.50.1 * libfreshclam2-0.103.11-150000.3.50.1 * clamav-devel-0.103.11-150000.3.50.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (ppc64le x86_64) *clamav-0.103.11-150000.3.50.1 * clamav-debuginfo-0.103.11-150000.3.50.1 * libclamav9-debuginfo-0.103.11-150000.3.50.1 * libfreshclam2-debuginfo-0.103.11-150000.3.50.1 * clamav-debugsource-0.103.11-150000.3.50.1 * libclamav9-0.103.11-150000.3.50.1 * libfreshclam2-0.103.11-150000.3.50.1 * clamav-devel-0.103.11-150000.3.50.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * clamav-0.103.11-150000.3.50.1 * clamav-debuginfo-0.103.11-150000.3.50.1 * libclamav9-debuginfo-0.103.11-150000.3.50.1 * libfreshclam2-debuginfo-0.103.11-150000.3.50.1 * clamav-debugsource-0.103.11-150000.3.50.1 * libclamav9-0.103.11-150000.3.50.1 * libfreshclam2-0.103.11-150000.3.50.1 * clamav-devel-0.103.11-150000.3.50.1 * SUSE Manager Proxy 4.2 (x86_64) * clamav-0.103.11-150000.3.50.1 * clamav-debuginfo-0.103.11-150000.3.50.1 * libclamav9-debuginfo-0.103.11-150000.3.50.1 * libfreshclam2-debuginfo-0.103.11-150000.3.50.1 * clamav-debugsource-0.103.11-150000.3.50.1 * libclamav9-0.103.11-150000.3.50.1 * libfreshclam2-0.103.11-150000.3.50.1 * clamav-devel-0.103.11-150000.3.50.1 * SUSE Manager Retail Branch Server 4.2 (x86_64) * clamav-0.103.11-150000.3.50.1 * clamav-debuginfo-0.103.11-150000.3.50.1 * libclamav9-debuginfo-0.103.11-150000.3.50.1 * libfreshclam2-debuginfo-0.103.11-150000.3.50.1 * clamav-debugsource-0.103.11-150000.3.50.1 * libclamav9-0.103.11-150000.3.50.1 * libfreshclam2-0.103.11-150000.3.50.1 * clamav-devel-0.103.11-150000.3.50.1 * SUSE Manager Server 4.2 (ppc64le s390x x86_64) * clamav-0.103.11-150000.3.50.1 * clamav-debuginfo-0.103.11-150000.3.50.1 * libclamav9-debuginfo-0.103.11-150000.3.50.1 * libfreshclam2-debuginfo-0.103.11-150000.3.50.1 * clamav-debugsource-0.103.11-150000.3.50.1 * libclamav9-0.103.11-150000.3.50.1 * libfreshclam2-0.103.11-150000.3.50.1 * clamav-devel-0.103.11-150000.3.50.1 * SUSE Enterprise Storage 7.1 (aarch64x86_64) * clamav-0.103.11-150000.3.50.1 * clamav-debuginfo-0.103.11-150000.3.50.1 * libclamav9-debuginfo-0.103.11-150000.3.50.1 * libfreshclam2-debuginfo-0.103.11-150000.3.50.1 * clamav-debugsource-0.103.11-150000.3.50.1 * libclamav9-0.103.11-150000.3.50.1 * libfreshclam2-0.103.11-150000.3.50.1 * clamav-devel-0.103.11-150000.3.50.1 * SUSE CaaS Platform 4.0 (x86_64) * clamav-0.103.11-150000.3.50.1 * clamav-debuginfo-0.103.11-150000.3.50.1 * libclamav9-debuginfo-0.103.11-150000.3.50.1 * libfreshclam2-debuginfo-0.103.11-150000.3.50.1 * clamav-debugsource-0.103.11-150000.3.50.1 * libclamav9-0.103.11-150000.3.50.1 * libfreshclam2-0.103.11-150000.3.50.1 * clamav-devel-0.103.11-150000.3.50.1 ## References: * https://www.suse.com/security/cve/CVE-2023-40477.html * https://bugzilla.suse.com/show_bug.cgi?id=1216625 . clamav upgrade patches CVE-2023-40477. Apply the newest update for essential repairs in SUSE versions.. clamav update, malware protection, SUSE security patch. . Severity: Important. LinuxSecurity.com Team
Important: thunderbird security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:0476", "synopsis": "Important: thunderbird security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for thunderbird.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Mozilla Thunderbird is a standalone mail and newsgroup client.\n\nThis update upgrades Thunderbird to version 102.7.1.\n\nSecurity Fix(es):\n\n* Mozilla: libusrsctp library out of date (CVE-2022-46871)\n\n* Mozilla: Arbitrary file read from GTK drag and drop on Linux (CVE-2023-23598)\n\n* Mozilla: Memory safety bugs fixed in Firefox 109 and Firefox ESR 102.7 (CVE-2023-23605)\n\n* Mozilla: Malicious command could be hidden in devtools output (CVE-2023-23599)\n\n* Mozilla: URL being dragged from cross-origin iframe into same tab triggers navigation (CVE-2023-23601)\n\n* Mozilla: Content Security Policy wasn't being correctly applied to WebSockets in WebWorkers (CVE-2023-23602)\n\n* Mozilla: Fullscreen notification bypass (CVE-2022-46877)\n\n* Mozilla: Calls to console.log allowed bypasing Content Security Policy via format directive (CVE-2023-23603)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2162336", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2162336", "description": ""}, {"ticket": "2162338", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2162338", "description": ""}, {"ticket": "2162339", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2162339", "description": ""}, {"ticket": "2162340", "sourceBy": "Red Hat", "sourceLink":"https://bugzilla.redhat.com/show_bug.cgi?id=2162340", "description": ""}, {"ticket": "2162341", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2162341", "description": ""}, {"ticket": "2162342", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2162342", "description": ""}, {"ticket": "2162343", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2162343", "description": ""}, {"ticket": "2162344", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2162344", "description": ""}], "cves": [{"name": "CVE-2022-46871", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-46871", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-1104"}, {"name": "CVE-2022-46877", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-46877", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N", "cvss3BaseScore": "4.3", "cwe": "CWE-357"}, {"name": "CVE-2023-23598", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-23598", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-450"}, {"name": "CVE-2023-23599", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-23599", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "cvss3BaseScore": "6.1", "cwe": "CWE-77"}, {"name": "CVE-2023-23601", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-23601", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "cvss3BaseScore": "6.1", "cwe": "CWE-829"}, {"name": "CVE-2023-23602", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-23602", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "cvss3BaseScore": "6.1", "cwe": "CWE-1385"}, {"name": "CVE-2023-23603", "sourceBy": "MITRE", "sourceLink":"https://www.cve.org/CVERecord?id=CVE-2023-23603", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N", "cvss3BaseScore": "6.5", "cwe": "CWE-185"}, {"name": "CVE-2023-23605", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-23605", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-120"}], "references": [], "publishedAt": "2023-01-26T17:04:32Z", "rpms": {"Rocky Linux 9": {"nvras": ["thunderbird-0:102.7.1-1.el9_1.aarch64.rpm", "thunderbird-0:102.7.1-1.el9_1.ppc64le.rpm", "thunderbird-0:102.7.1-1.el9_1.s390x.rpm", "thunderbird-0:102.7.1-1.el9_1.src.rpm", "thunderbird-0:102.7.1-1.el9_1.x86_64.rpm", "thunderbird-debuginfo-0:102.7.1-1.el9_1.aarch64.rpm", "thunderbird-debuginfo-0:102.7.1-1.el9_1.ppc64le.rpm", "thunderbird-debuginfo-0:102.7.1-1.el9_1.s390x.rpm", "thunderbird-debuginfo-0:102.7.1-1.el9_1.x86_64.rpm", "thunderbird-debugsource-0:102.7.1-1.el9_1.aarch64.rpm", "thunderbird-debugsource-0:102.7.1-1.el9_1.ppc64le.rpm", "thunderbird-debugsource-0:102.7.1-1.el9_1.s390x.rpm", "thunderbird-debugsource-0:102.7.1-1.el9_1.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. The latest Thunderbird patch for Rocky Linux enhances its security measures, effectively bolstering the email client's protection against various cyber threats.. Thunderbird Security, Rocky Linux Update, Security Fixes, Open Source Email, Linux Client Protection. . Severity: Important. LinuxSecurity.com Team
Update to bugfix release 4.1.0 Security fix for CVE-2017-9438, CVE-2021-3402, CVE-2019-19648, CVE-2017-9438. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-dd62918333 2021-05-06 00:52:28.374770 --------------------------------------------------------------------------------Name : python-yara Product : Fedora 33 Version : 4.1.0 Release : 1.fc33 URL : https://github.com/VirusTotal/yara-python/ Summary : Python binding for the YARA pattern matching tool Description : Python binding for the YARA pattern matching tool. YARA is a tool aimed at (but not limited to) helping malware researchers to identify and classify malware samples. With YARA you can create descriptions of malware families (or whatever you want to describe) based on textual or binary patterns. Each description, a.k.a rule, consists of a set of strings and a Boolean expression which determine its logic. --------------------------------------------------------------------------------Update Information: Update to bugfix release 4.1.0 Security fix for CVE-2017-9438, CVE-2021-3402, CVE-2019-19648, CVE-2017-9438 --------------------------------------------------------------------------------ChangeLog: * Tue Apr 27 2021 Michal Ambroz - 4.1.0-1 - bump the python-yara as well to 4.1.0 * Tue Apr 27 2021 Michal Ambroz - 4.0.5-3 - rebuild for new version of yara 4.1.0 * Sun Apr 25 2021 Michal Ambroz - 4.0.5-2 - rebuild for epel * Sat Mar 13 2021 Michal Ambroz - 4.0.5-1 - bump to version 4.0.5 * Wed Feb 10 2021 Michal Ambroz - 4.0.4-1 - bump to version 4.0.4 * Thu Feb 4 2021 Michal Ambroz - 4.0.3-1 - bump to version 4.0.3 * Wed Jan 27 2021 Fedora Release Engineering - 4.0.2-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1459012 - CVE-2017-9438 yara: Stack consumption via acrafted rule mishandled in the _ur_re_emit function https://bugzilla.redhat.com/show_bug.cgi?id=1459012 [ 2 ] Bug #1930175 - CVE-2021-3402 libyara: Integer overflow in libyara/modules/macho/macho.c via a malicious Mach-O file https://bugzilla.redhat.com/show_bug.cgi?id=1930175 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-dd62918333' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update that solves three vulnerabilities and has one errata is now available. . SUSE Security Update: Security update for clamav ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:14692-1 Rating: important References: #1181256 #1184532 #1184533 #1184534 Cross-References: CVE-2021-1252 CVE-2021-1404 CVE-2021-1405 CVSS scores: CVE-2021-1252 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-1404 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-1405 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise Server 11-SP4-LTSS SUSE Linux Enterprise Point of Sale 11-SP3 SUSE Linux Enterprise Debuginfo 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP3 ______________________________________________________________________________ An update that solves three vulnerabilities and has one errata is now available. Description: This update for clamav fixes the following issues: - CVE-2021-1252: Fix for Excel XLM parser infinite loop. (bsc#1184532) - CVE-2021-1404: Fix for PDF parser buffer over-read; possible crash. (bsc#1184533) - CVE-2021-1405: Fix for mail parser NULL-dereference crash. (bsc#1184534) - Fix errors when scanning files > 4G (bsc#1181256) - Update clamav.keyring - Update to 0.103.2 Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4-LTSS: zypper in -t patch slessp4-clamav-14692=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patch sleposp3-clamav-14692=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -tpatch dbgsp4-clamav-14692=1 - SUSE Linux Enterprise Debuginfo 11-SP3: zypper in -t patch dbgsp3-clamav-14692=1 Package List: - SUSE Linux Enterprise Server 11-SP4-LTSS (i586 ppc64 s390x x86_64): clamav-0.103.2-0.20.35.1 - SUSE Linux Enterprise Point of Sale 11-SP3 (i586): clamav-0.103.2-0.20.35.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ppc64 s390x x86_64): clamav-debuginfo-0.103.2-0.20.35.1 clamav-debugsource-0.103.2-0.20.35.1 - SUSE Linux Enterprise Debuginfo 11-SP3 (i586 s390x x86_64): clamav-debuginfo-0.103.2-0.20.35.1 clamav-debugsource-0.103.2-0.20.35.1 References: https://www.suse.com/security/cve/CVE-2021-1252.html https://www.suse.com/security/cve/CVE-2021-1404.html https://www.suse.com/security/cve/CVE-2021-1405.html https://bugzilla.suse.com/1181256 https://bugzilla.suse.com/1184532 https://bugzilla.suse.com/1184533 https://bugzilla.suse.com/1184534 . SUSE Security Patch for ClamAV addresses various vulnerabilities. Apply the update promptly to ensure system security and efficiency.. SUSE Update, ClamAV Security, Important Security Fixes. . Severity: Important. LinuxSecurity.com Team
Damian Put discovered a vulnerability in the ClamAV anti-virus toolkit's parsing of Petite-packed Win32 executables. The weakness leads to an invalid memory access, and could enable an attacker to crash clamav by supplying a maliciously crafted Petite-compressed binary for scanning. In some configurations, such as when clamav is used in combination with mail servers, this could cause a system to "fail open," facilitating a follow-on viral attack.. - ------------------------------------------------------------------------Debian Security Advisory DSA-1616-2
Clam AntiVirus is vulnerable to integer overflows when handling several file formats, potentially resulting in the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200507-25 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Clam AntiVirus: Integer overflows Date: July 26, 2005 Bugs: #100178 ID: 200507-25 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Clam AntiVirus is vulnerable to integer overflows when handling several file formats, potentially resulting in the execution of arbitrary code. Background ========= Clam AntiVirus is a GPL anti-virus toolkit, designed for integration with mail servers to perform attachment scanning. Clam AntiVirus also provides a command line scanner and a tool for fetching updates of the virus database. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-antivirus/clamav < 0.86.2 > = 0.86.2 Description ========== Neel Mehta and Alex Wheeler discovered that Clam AntiVirus is vulnerable to integer overflows when handling the TNEF, CHM and FSG file formats. Impact ===== By sending a specially-crafted file an attacker could execute arbitrary code with the permissions of the user running Clam AntiVirus. Workaround ========= There is no known workaround at this time. Resolution ========= All Clam AntiVirus users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-antivirus/clamav-0.86.2" References ========= [ 1 ] BugTraqAnnouncement [ 2 ] Clam AntiVirus: Release Notes Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200507-25 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.