ClamAV 0.100.2 has been released!

"Joel Esler (jesler)" <[email protected]> Wed, 3 Oct 2018 17:37:55 +0000
Newsgroups gmane.comp.security.virus.clamav.announce,gmane.comp.security.virus.clamav.user
Message-ID <[email protected]>
--===============4684146631946202416==
Content-Language: en-US
Content-Type: multipart/alternative;
	boundary="_000_16FA90D15C464A22A1B6FD97C06D4BA5ciscocom_"

--_000_16FA90D15C464A22A1B6FD97C06D4BA5ciscocom_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

https://blog.clamav.net/2018/10/clamav-01002-has-been-released.html

ClamAV 0.100.2 has been released!

ClamAV 0.100.2 is a patch release to address a set of vulnerabilities.



  *   Fixes for the following ClamAV vulnerabilities:
     *   CVE-2018-15378<https://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCV=
E-2018-15378>:
        *   Vulnerability in ClamAV's MEW unpacking feature that could allo=
w an unauthenticated, remote attacker to cause a denial of service (DoS) co=
ndition on an affected device.
        *   Reported by Secunia Research at Flexera.
     *   Fix for a 2-byte buffer over-read bug in ClamAV's PDF parsing code=
.
        *   Reported by Alex Gaynor.
     *   Fixes for the following vulnerabilities in bundled third-party lib=
raries:
     *   CVE-2018-14680<https://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCV=
E-2018-14680>:
        *   An issue was discovered in mspack/chmd.c in libmspack before 0.=
7alpha. It does not reject blank CHM filenames.
     *   CVE-2018-14681<https://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCV=
E-2018-14681>:
        *   An issue was discovered in kwajd_read_headers in mspack/kwajd.c=
 in libmspack before 0.7alpha. Bad KWAJ file header extensions could cause =
a one or two byte overwrite.
     *   CVE-2018-14682<https://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCV=
E-2018-14682>:
        *   An issue was discovered in mspack/chmd.c in libmspack before 0.=
7alpha. There is an off-by-one error in the TOLOWER() macro for CHM decompr=
ession. Additionally, 0.100.2 reverted 0.100.1's patch for CVE-2018-14679, =
and applied libmspack's version of the fix in its place
  *   Other changes:
     *   Some users have reported freshclam signature update failures as a =
result of a delay between the time the new signature database content is an=
nounced and the time that the content-delivery-network has the content avai=
lable for download. To mitigate these errors, this patch release includes s=
ome modifications to freshclam to make it more lenient, and to reduce the t=
ime that freshclam will ignore a mirror when it detects an issue.
     *   On-Access "Extra Scanning", an opt-in minor feature of OnAccess sc=
anning on Linux systems, has been disabled due to a known issue with resour=
ce cleanup OnAccessExtraScanning will be re-enabled in a future release whe=
n the issue is resolved. In the mean-time, users who enabled the feature in=
 clamd.conf will see a warning informing them that the feature is not activ=
e. For details, see: https://bugzilla.clamav.net/show_bug.cgi?id=3D12048


Thank you to the following ClamAV community members for your code submissio=
ns
and bug reports!

- Alex Gaynor
- Hiroya Ito
- Laurent Delosieres, Secunia Research at Flexera


--_000_16FA90D15C464A22A1B6FD97C06D4BA5ciscocom_
Content-Type: text/html; charset="us-ascii"
Content-ID: <[email protected]>
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
</head>
<body style=3D"word-wrap: break-word; -webkit-nbsp-mode: space; line-break:=
 after-white-space;" class=3D"">
<div style=3D"margin: 0px;" class=3D""><font face=3D"-webkit-standard" clas=
s=3D""><a href=3D"https://blog.clamav.net/2018/10/clamav-01002-has-been-rel=
eased.html" class=3D"">https://blog.clamav.net/2018/10/clamav-01002-has-bee=
n-released.html</a></font></div>
<div style=3D"margin: 0px; font-family: -webkit-standard;" class=3D""><br c=
lass=3D"">
</div>
<div style=3D"margin: 0px; font-family: -webkit-standard;" class=3D"">ClamA=
V 0.100.2 has been released!</div>
<div style=3D"margin: 0px; font-family: -webkit-standard;" class=3D""><br c=
lass=3D"">
</div>
<div style=3D"margin: 0px; font-family: -webkit-standard;" class=3D"">ClamA=
V 0.100.2 is a patch release to address a set of vulnerabilities.</div>
<div style=3D"margin: 0px; font-family: -webkit-standard;" class=3D""><br c=
lass=3D"">
</div>
<div style=3D"margin: 0px; font-family: -webkit-standard;" class=3D""><br c=
lass=3D"">
</div>
<ul style=3D"font-family: -webkit-standard;" class=3D"">
<li class=3D"">Fixes for the following ClamAV vulnerabilities:
<ul class=3D"">
<li class=3D""><a data-blogger-escaped-target=3D"_blank" href=3D"https://cv=
e.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2018-15378" class=3D"">CVE-2018-=
15378</a>:
<ul class=3D"">
<li class=3D"">Vulnerability in ClamAV's MEW unpacking feature that could a=
llow an unauthenticated, remote attacker to cause a denial of service (DoS)=
 condition on an affected device.</li><li class=3D"">Reported by Secunia Re=
search at Flexera.</li></ul>
</li><li class=3D"">Fix for a 2-byte buffer over-read bug in ClamAV's PDF p=
arsing code.
<ul class=3D"">
<li class=3D"">Reported by Alex Gaynor.</li></ul>
</li><li class=3D"">Fixes for the following vulnerabilities in bundled thir=
d-party libraries:</li><li class=3D""><a data-blogger-escaped-target=3D"_bl=
ank" href=3D"https://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2018-1468=
0" class=3D"">CVE-2018-14680</a>:
<ul class=3D"">
<li class=3D"">An issue was discovered in mspack/chmd.c in libmspack before=
 0.7alpha. It does not reject blank CHM filenames.</li></ul>
</li><li class=3D""><a data-blogger-escaped-target=3D"_blank" href=3D"https=
://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2018-14681" class=3D"">CVE-=
2018-14681</a>:
<ul class=3D"">
<li class=3D"">An issue was discovered in kwajd_read_headers in mspack/kwaj=
d.c in libmspack before 0.7alpha. Bad KWAJ file header extensions could cau=
se a one or two byte overwrite.</li></ul>
</li><li class=3D""><a data-blogger-escaped-target=3D"_blank" href=3D"https=
://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2018-14682" class=3D"">CVE-=
2018-14682</a>:
<ul class=3D"">
<li class=3D"">An issue was discovered in mspack/chmd.c in libmspack before=
 0.7alpha. There is an off-by-one error in the TOLOWER() macro for CHM deco=
mpression. Additionally, 0.100.2 reverted 0.100.1's patch for CVE-2018-1467=
9, and applied libmspack's version
 of the fix in its place</li></ul>
</li></ul>
</li><li class=3D"">Other changes:
<ul class=3D"">
<li class=3D"">Some users have reported freshclam signature update failures=
 as a result of a delay between the time the new signature database content=
 is announced and the time that the content-delivery-network has the conten=
t available for download. To mitigate
 these errors, this patch release includes some modifications to freshclam =
to make it more lenient, and to reduce the time that freshclam will ignore =
a mirror when it detects an issue.</li><li class=3D"">On-Access &quot;Extra=
 Scanning&quot;, an opt-in minor feature of OnAccess scanning on Linux syst=
ems, has been disabled due to a known issue with resource cleanup OnAccessE=
xtraScanning will be re-enabled in a future release when the issue is resol=
ved. In
 the mean-time, users who enabled the feature in clamd.conf will see a warn=
ing informing them that the feature is not active. For details, see:&nbsp;<=
a href=3D"https://bugzilla.clamav.net/show_bug.cgi?id=3D12048" class=3D"">h=
ttps://bugzilla.clamav.net/show_bug.cgi?id=3D12048</a></li></ul>
</li></ul>
<div style=3D"margin: 0px; font-family: -webkit-standard;" class=3D""><br c=
lass=3D"">
</div>
<div style=3D"margin: 0px; font-family: -webkit-standard;" class=3D""><br c=
lass=3D"">
</div>
<div style=3D"margin: 0px; font-family: -webkit-standard;" class=3D"">Thank=
 you to the following ClamAV community members for your code submissions</d=
iv>
<div style=3D"margin: 0px; font-family: -webkit-standard;" class=3D"">and b=
ug reports!</div>
<div style=3D"margin: 0px; font-family: -webkit-standard;" class=3D""><br c=
lass=3D"">
</div>
<div style=3D"margin: 0px; font-family: -webkit-standard;" class=3D"">- Ale=
x Gaynor</div>
<div style=3D"margin: 0px; font-family: -webkit-standard;" class=3D"">- Hir=
oya Ito</div>
<div style=3D"margin: 0px; font-family: -webkit-standard;" class=3D"">- Lau=
rent Delosieres, Secunia Research at Flexera</div>
<div class=3D""><br class=3D"">
</div>
<div style=3D"font-family: -webkit-standard;" class=3D""></div>
</body>
</html>

--_000_16FA90D15C464A22A1B6FD97C06D4BA5ciscocom_--

--===============4684146631946202416==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-announce
http://www.clamav.net/contact.html#ml

--===============4684146631946202416==--