MGASA-2019-0361

Source
https://advisories.mageia.org/MGASA-2019-0361.html
Import Source
https://advisories.mageia.org/MGASA-2019-0361.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2019-0361
Related
Published
2019-12-06T14:15:42Z
Modified
2019-12-06T13:42:08Z
Summary
Updated clamav packages fix security vulnerability
Details

The updated packages fix two packaging problems and a security vulnerability:

A Denial-of-Service (DoS) vulnerability may occur when scanning a specially crafted email file as a result of excessively long scan times. (CVE-2019-15961)

The first packaging issue, in the configuration of clamav-daemon.socket, leads to freshclam and amavis complaining about not being able to access clamd socket.

The second packaging issue, in the names of systemd services, leads to warnigs at the installation/update of clamav and clamd.

References
Credits

Affected packages

Mageia:7 / clamav

Package

Name
clamav
Purl
pkg:rpm/mageia/clamav?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.101.5-1.1.mga7

Ecosystem specific

{
    "section": "core"
}