MGASA-2019-0328

Source
https://advisories.mageia.org/MGASA-2019-0328.html
Import Source
https://advisories.mageia.org/MGASA-2019-0328.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2019-0328
Related
Published
2019-11-19T21:16:53Z
Modified
2019-11-19T20:47:47Z
Summary
Updated clamav packages fix security vulnerabilities
Details

The updated packages fix security vulnerabilities:

ClamAV versions prior to 0.101.3 are susceptible to a zip bomb vulnerability where an unauthenticated attacker can cause a denial of service condition by sending crafted messages to an affected system. (CVE-2019-12625)

BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors. (CVE-2019-12900)

References
Credits

Affected packages

Mageia:7 / clamav

Package

Name
clamav
Purl
pkg:rpm/mageia/clamav?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.101.4-1.1.mga7

Ecosystem specific

{
    "section": "core"
}

Mageia:7 / c-icap-modules-extra

Package

Name
c-icap-modules-extra
Purl
pkg:rpm/mageia/c-icap-modules-extra?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.3-1.mga7

Ecosystem specific

{
    "section": "core"
}

Mageia:7 / ecap-clamav

Package

Name
ecap-clamav
Purl
pkg:rpm/mageia/ecap-clamav?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.0-3.1.mga7

Ecosystem specific

{
    "section": "core"
}