ClamAV® blog: ClamAV 0.10 2.1 and 0.101.5 patches have been released!

"Joel Esler (jesler)" <[email protected]> Wed, 20 Nov 2019 18:32:21 +0000
Newsgroups gmane.comp.security.virus.clamav.announce,gmane.comp.security.virus.clamav.user,gmane.comp.security.virus.clamav.devel
Message-ID <[email protected]>
--===============8249337381845373736==
Content-Language: en-US
Content-Type: multipart/alternative;
	boundary="_000_8EE36B58310743B587D320F2C0B871A1ciscocom_"

--_000_8EE36B58310743B587D320F2C0B871A1ciscocom_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable



https://blog.clamav.net/2019/11/clamav-01021-and-01015-patches-have.html

ClamAV 0.102.1 and 0.101.5 patches have been released!
Today we are publishing two patch versions, 0.102.1 and 0.101.5.  Both of t=
hese can be found on ClamAV's downloads<http://www.clamav.net/downloads> pa=
ge, with 0.102.1 as the main release and 0.101.5 under "Previous Stable Rel=
eases."

0.102.1
ClamAV 0.102.1 is a security patch release to address the following issues.



  *   Fix for the following vulnerability affecting 0.102.0 and 0.101.4 and=
 prior:
     *   CVE-2019-15961<https://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCV=
E-2019-15961>:
        *   A Denial-of-Service (DoS) vulnerability may occur when scanning=
 a specially crafted email file as a result of excessively long scan times.=
 The issue is resolved by implementing several maximums in parsing MIME mes=
sages and by optimizing use of memory allocation.
  *   Build system fixes to build clamav-milter, to correctly link with lib=
xml2 when detected, and to correctly detect fanotify for on-access scanning=
 feature support.
  *   Signature load time is significantly reduced by changing to a more ef=
ficient algorithm for loading signature patterns and allocating the AC trie=
. Patch courtesy of Alberto Wu.
  *   Introduced a new configure option to statically link libjson-c with l=
ibclamav. Static linking with libjson is highly recommended to prevent cras=
hes in applications that use libclamav alongside another JSON parsing libra=
ry.
  *   Null-dereference fix in email parser when using the --gen-json metada=
ta option.
  *   Fixes for Authenticode parsing and certificate signature (.crb databa=
se) bugs.


Special thanks to the following for code contributions and bug reports:

- Alberto Wu
- Joran Dirk Greef
- Reio Remma

0.101.5
ClamAV 0.101.5 is a security patch release that addresses the following iss=
ues.



  *   Fix for the following vulnerability affecting 0.102.0 and 0.101.4 and=
 prior:
     *   CVE-2019-15961<https://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCV=
E-2019-15961>:
        *   A Denial-of-Service (DoS) vulnerability may occur when scanning=
 a specially crafted email file as a result of excessively long scan times.=
 The issue is resolved by implementing several maximums in parsing MIME mes=
sages and by optimizing use of memory allocation.
  *   Added the zip scanning improvements found in v0.102.0 where it scans =
files using zip records from a sorted catalogue which provides deduplicatio=
n of file records resulting in faster extraction and scan time and reducing=
 the likelihood of alerting on non-malicious duplicate file entries as over=
lapping files.
  *   Signature load time is significantly reduced by changing to a more ef=
ficient algorithm for loading signature patterns and allocating the AC trie=
. Patch courtesy of Alberto Wu.
  *   Introduced a new configure option to statically link libjson-c with l=
ibclamav. Static linking with libjson is highly recommended to prevent cras=
hes in applications that use libclamav alongside another JSON parsing libra=
ry.
  *   Null-dereference fix in email parser when using the --gen-json metada=
ta option.


Special thanks to the following for code contributions and bug reports:

- Alberto Wu
- Joran Dirk Greef

Please join us on the ClamAV mailing lists<https://www.clamav.net/contact#m=
l> for further discussion!  Thanks!

--_000_8EE36B58310743B587D320F2C0B871A1ciscocom_
Content-Type: text/html; charset="iso-8859-1"
Content-ID: <[email protected]>
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<base>
</head>
<body style=3D"word-wrap: break-word; -webkit-nbsp-mode: space; line-break:=
 after-white-space;" class=3D"">
<base class=3D"">
<div class=3D"Apple-Mail-URLShareUserContentTopClass"><br class=3D"">
</div>
<div class=3D"Apple-Mail-URLShareWrapperClass">
<blockquote type=3D"cite" style=3D"border-left-style: none; color: inherit;=
 padding: inherit; margin: inherit;" class=3D"">
<div class=3D"">
<div class=3D"original-url"><br class=3D"">
<a href=3D"https://blog.clamav.net/2019/11/clamav-01021-and-01015-patches-h=
ave.html" class=3D"">https://blog.clamav.net/2019/11/clamav-01021-and-01015=
-patches-have.html</a><br class=3D"">
<br class=3D"">
</div>
<div id=3D"article" role=3D"article" style=3D"text-rendering: optimizeLegib=
ility; font-family: -apple-system-font; font-size: 1.2em; line-height: 1.5e=
m; margin: 0px; padding: 0px;" class=3D"system exported">
<!-- This node will contain a number of div.page. -->
<div class=3D"page" style=3D"word-wrap: break-word; max-width: 100%;">
<h1 class=3D"title" style=3D"font-size: 1.95552em; line-height: 1.2141em; m=
argin-top: 0px; margin-bottom: 0.5em; max-width: 100%;">
ClamAV 0.102.1 and 0.101.5 patches have been released!</h1>
Today we are publishing two patch versions, 0.102.1 and 0.101.5.&nbsp; Both=
 of these can be found on
<a href=3D"http://www.clamav.net/downloads" target=3D"_blank" style=3D"colo=
r: rgb(73, 129, 254); max-width: 100%;" class=3D"">
ClamAV's downloads</a> page, with 0.102.1 as the main release and 0.101.5 u=
nder &quot;Previous Stable Releases.&quot;<br style=3D"max-width: 100%;" cl=
ass=3D"">
<br style=3D"max-width: 100%;" class=3D"">
<h3 style=3D"font-size: 1.25em; max-width: 100%;" class=3D"">0.102.1</h3>
ClamAV 0.102.1 is a security patch release to address the following issues.=
<br style=3D"max-width: 100%;" class=3D"">
<br style=3D"max-width: 100%;" class=3D"">
<br style=3D"max-width: 100%;" class=3D"">
<ul style=3D"max-width: 100%;" class=3D"">
<li style=3D"max-width: 100%;" class=3D"">Fix for the following vulnerabili=
ty affecting 0.102.0 and 0.101.4 and prior:</li><ul style=3D"max-width: 100=
%;" class=3D"">
<li style=3D"max-width: 100%;" class=3D""><a href=3D"https://cve.mitre.org/=
cgi-bin/cvename.cgi?name=3DCVE-2019-15961" rel=3D"nofollow" target=3D"_blan=
k" style=3D"color: rgb(73, 129, 254); max-width: 100%;" class=3D"">CVE-2019=
-15961</a>:</li><ul style=3D"max-width: 100%;" class=3D"">
<li style=3D"max-width: 100%;" class=3D"">A Denial-of-Service (DoS) vulnera=
bility may occur when scanning a specially crafted email file as a result o=
f excessively long scan times. The issue is resolved by implementing severa=
l maximums in parsing MIME messages
 and by optimizing use of memory allocation.</li></ul>
</ul>
<li style=3D"max-width: 100%;" class=3D"">Build system fixes to build clama=
v-milter, to correctly link with libxml2 when detected, and to correctly de=
tect fanotify for on-access scanning feature support.</li><li style=3D"max-=
width: 100%;" class=3D"">Signature load time is significantly reduced by ch=
anging to a more efficient algorithm for loading signature patterns and all=
ocating the AC trie. Patch courtesy of Alberto Wu.</li><li style=3D"max-wid=
th: 100%;" class=3D"">Introduced a new configure option to statically link =
libjson-c with libclamav. Static linking with libjson is highly recommended=
 to prevent crashes in applications that use libclamav alongside another JS=
ON parsing library.</li><li style=3D"max-width: 100%;" class=3D"">Null-dere=
ference fix in email parser when using the
<span style=3D"max-width: 100%;" class=3D"">--gen-json</span> metadata opti=
on.</li><li style=3D"max-width: 100%;" class=3D"">Fixes for Authenticode pa=
rsing and certificate signature (.crb database) bugs.</li></ul>
<br style=3D"max-width: 100%;" class=3D"">
<br style=3D"max-width: 100%;" class=3D"">
Special thanks to the following for code contributions and bug reports:<br =
style=3D"max-width: 100%;" class=3D"">
<br style=3D"max-width: 100%;" class=3D"">
- Alberto Wu<br style=3D"max-width: 100%;" class=3D"">
- Joran Dirk Greef<br style=3D"max-width: 100%;" class=3D"">
- Reio Remma<br style=3D"max-width: 100%;" class=3D"">
<br style=3D"max-width: 100%;" class=3D"">
<h3 style=3D"font-size: 1.25em; max-width: 100%;" class=3D"">0.101.5</h3>
ClamAV 0.101.5 is a security patch release that addresses the following iss=
ues.<br style=3D"max-width: 100%;" class=3D"">
<br style=3D"max-width: 100%;" class=3D"">
<br style=3D"max-width: 100%;" class=3D"">
<ul style=3D"max-width: 100%;" class=3D"">
<li style=3D"max-width: 100%;" class=3D"">Fix for the following vulnerabili=
ty affecting 0.102.0 and 0.101.4 and prior:</li><ul style=3D"max-width: 100=
%;" class=3D"">
<li style=3D"max-width: 100%;" class=3D""><a href=3D"https://cve.mitre.org/=
cgi-bin/cvename.cgi?name=3DCVE-2019-15961" rel=3D"nofollow" target=3D"_blan=
k" style=3D"color: rgb(73, 129, 254); max-width: 100%;" class=3D"">CVE-2019=
-15961</a>:</li><ul style=3D"max-width: 100%;" class=3D"">
<li style=3D"max-width: 100%;" class=3D"">A Denial-of-Service (DoS) vulnera=
bility may occur when scanning a specially crafted email file as a result o=
f excessively long scan times. The issue is resolved by implementing severa=
l maximums in parsing MIME messages
 and by optimizing use of memory allocation.</li></ul>
</ul>
<li style=3D"max-width: 100%;" class=3D"">Added the zip scanning improvemen=
ts found in v0.102.0 where it scans files using zip records from a sorted c=
atalogue which provides deduplication of file records resulting in faster e=
xtraction and scan time and reducing
 the likelihood of alerting on non-malicious duplicate file entries as over=
lapping files.</li><li style=3D"max-width: 100%;" class=3D"">Signature load=
 time is significantly reduced by changing to a more efficient algorithm fo=
r loading signature patterns and allocating the AC trie. Patch courtesy of =
Alberto Wu.</li><li style=3D"max-width: 100%;" class=3D"">Introduced a new =
configure option to statically link libjson-c with libclamav. Static linkin=
g with libjson is highly recommended to prevent crashes in applications tha=
t use libclamav alongside another JSON parsing library.</li><li style=3D"ma=
x-width: 100%;" class=3D"">Null-dereference fix in email parser when using =
the
<span style=3D"max-width: 100%;" class=3D"">--gen-json</span> metadata opti=
on.</li></ul>
<br style=3D"max-width: 100%;" class=3D"">
<br style=3D"max-width: 100%;" class=3D"">
Special thanks to the following for code contributions and bug reports:<br =
style=3D"max-width: 100%;" class=3D"">
<br style=3D"max-width: 100%;" class=3D"">
- Alberto Wu<br style=3D"max-width: 100%;" class=3D"">
- Joran Dirk Greef<br style=3D"max-width: 100%;" class=3D"">
<br style=3D"max-width: 100%;" class=3D"">
Please join us on the <a href=3D"https://www.clamav.net/contact#ml" target=
=3D"_blank" style=3D"color: rgb(73, 129, 254); max-width: 100%;" class=3D""=
>
ClamAV mailing lists</a> for further discussion! &nbsp;Thanks! &nbsp;&nbsp;=
</div>
</div>
</div>
</blockquote>
</div>
</body>
</html>

--_000_8EE36B58310743B587D320F2C0B871A1ciscocom_--

--===============8249337381845373736==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________

clamav-announce mailing list
[email protected]
https://lists.clamav.net/mailman/listinfo/clamav-announce

http://www.clamav.net/contact.html#ml

--===============8249337381845373736==--