ClamAV® blog: ClamAV 0.10 3.2 security patch release

"Joel Esler (jesler)" <[email protected]> Wed, 7 Apr 2021 18:06:01 +0000
Newsgroups gmane.comp.security.virus.clamav.announce
Message-ID <C4F48818-34A6-4EB6-83E9-3D96D5C6FA1C__31360.2045107231$1617818957$gmane$org@cisco.com>
--===============7410036279193947545==
Content-Language: en-US
Content-Type: multipart/signed;
	boundary="Apple-Mail=_A92225D4-1087-475B-89CE-BECAC1B8B495";
	protocol="application/pgp-signature";
	micalg=pgp-sha1

--Apple-Mail=_A92225D4-1087-475B-89CE-BECAC1B8B495
Content-Type: multipart/alternative;
	boundary="Apple-Mail=_221300CE-70DB-4D88-BC62-3C819BB34050"


--Apple-Mail=_221300CE-70DB-4D88-BC62-3C819BB34050
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=us-ascii


>=20
> =
https://blog.clamav.net/2021/04/clamav-01032-security-patch-release.html =
<https://blog.clamav.net/2021/04/clamav-01032-security-patch-release.html>=

>=20
> ClamAV 0.103.2 security patch release
>=20
> Wednesday, April 7, 2021
>=20
>  <>ClamAV 0.103.2 is out now. Users can head over to =
clamav.net/downloads <https://www.clamav.net/downloads> to download the =
release materials.
>=20
> ClamAV 0.103.2 is a security patch release with the following fixes:
>=20
> CVE-2021-1386 =
<https://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2021-1386>: Fix =
for UnRAR DLL load privilege escalation. Affects 0.103.1 and prior on =
Windows only.
>=20
> CVE-2021-1252 =
<https://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2021-1252>: Fix =
for Excel XLM parser infinite loop. Affects 0.103.0 and 0.103.1 only.
>=20
> CVE-2021-1404 =
<https://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2021-1404>: Fix =
for PDF parser buffer over-read; possible crash. Affects 0.103.0 and =
0.103.1 only.
>=20
> CVE-2021-1405 =
<https://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2021-1405>: Fix =
for mail parser NULL-dereference crash. Affects 0.103.1 and prior.
>=20
> Fix possible memory leak in PNG parser.
>=20
> Fix ClamOnAcc scan on file-creation race condition so files are =
scanned after their contents are written.
>=20
> FreshClam: Deprecate the SafeBrowsing config option. The SafeBrowsing =
option will no longer do anything.
>=20
> For more details, see our blog post from last year about the future of =
the ClamAV Safe Browsing database =
<https://blog.clamav.net/2020/06/the-future-of-clamav-safebrowsing.html>.
>=20
> Tip: If creating and hosting your own safebrowing.gdb database, you =
can use the DatabaseCustomURL option in freshclam.conf to download it.
>=20
> FreshClam: Improved HTTP 304, 403, & 429 handling.
>=20
> FreshClam: Added back the mirrors.dat file to the database directory.
>=20
> This new mirrors.dat file will store:
> A randomly generated UUID for the FreshClam User-Agent.
> A retry-after timestamp that so FreshClam won't try to update after =
having received an HTTP 429 response until the Retry-After timeout has =
expired.
>=20
> FreshClam will now exit with a failure in daemon mode if an HTTP 403 =
(Forbidden) was received, because retrying later won't help any. The =
FreshClam user will have to take actions to get unblocked.
>=20
> Fix the FreshClam mirror-sync issue where a downloaded database is =
"older than the version advertised."
>=20
> If a new CVD download gets a version that is older than advertised, =
FreshClam will keep the older version and retry the update so that the =
incremental update process (CDIFF patch process) will update to the =
latest version.
> Labels: 0.103.2 <https://blog.clamav.net/search/label/0.103.2>, clamav =
<https://blog.clamav.net/search/label/clamav>, release =
<https://blog.clamav.net/search/label/release>

--Apple-Mail=_221300CE-70DB-4D88-BC62-3C819BB34050
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=us-ascii

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; =
charset=3Dus-ascii"><base></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;" class=3D""><base=
 class=3D""><div class=3D"Apple-Mail-URLShareUserContentTopClass"><br =
class=3D""></div><div =
class=3D"Apple-Mail-URLShareWrapperClass"><blockquote type=3D"cite" =
style=3D"border-left-style: none; color: inherit; padding: inherit; =
margin: inherit;" class=3D""><div class=3D""><div =
class=3D"original-url"><br class=3D""><a =
href=3D"https://blog.clamav.net/2021/04/clamav-01032-security-patch-releas=
e.html" =
class=3D"">https://blog.clamav.net/2021/04/clamav-01032-security-patch-rel=
ease.html</a><br class=3D""><br class=3D""></div><div id=3D"article" =
role=3D"article" style=3D"font-family: Georgia; text-rendering: =
optimizeLegibility; font-size: 1.2em; line-height: 1.5em; margin: 0px; =
padding: 0px;" class=3D"georgia exported">
        <!-- This node will contain a number of div.page. -->
    <div class=3D"page" style=3D"word-wrap: break-word; max-width: =
100%;"><h1 class=3D"title" style=3D"font-size: 1.95552em; line-height: =
1.2141em; margin-top: 0px; margin-bottom: 0.5em; max-width: =
100%;">ClamAV 0.103.2 security patch release</h1>
                                     =20
<h2 style=3D"font-size: 1.43em; max-width: 100%;" class=3D"">
<span style=3D"max-width: 100%;" class=3D"">
Wednesday, April 7, 2021
</span>
</h2>

                                        <div class=3D"clear" =
style=3D"max-width: 100%; clear: both;">
                                     =20
<div style=3D"max-width: 100%;" class=3D"">
<div itemprop=3D"blogPost" itemscope=3D"itemscope" =
itemtype=3D"http://schema.org/BlogPosting" style=3D"max-width: 100%;" =
class=3D"">


<a name=3D"4759003852411220873" style=3D"max-width: 100%;" class=3D""></a>=



<div itemprop=3D"description articleBody" style=3D"max-width: 100%;" =
class=3D""><p style=3D"max-width: 100%;" class=3D"">ClamAV 0.103.2 is =
out now. Users can head over to <a =
href=3D"https://www.clamav.net/downloads" target=3D"_blank" =
style=3D"color: rgb(73, 129, 254); max-width: 100%;" =
class=3D"">clamav.net/downloads</a> to download the release =
materials.<br style=3D"max-width: 100%;" class=3D""><br =
style=3D"max-width: 100%;" class=3D"">ClamAV 0.103.2 is a security patch =
release with the following fixes:</p><ul style=3D"max-width: 100%;" =
class=3D""><li style=3D"max-width: 100%;" class=3D""><a =
href=3D"https://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2021-1386" =
rel=3D"nofollow" target=3D"_blank" style=3D"color: rgb(73, 129, 254); =
max-width: 100%;" class=3D"">CVE-2021-1386</a>: Fix for UnRAR DLL load =
privilege escalation. Affects 0.103.1 and prior on Windows only.<br =
style=3D"max-width: 100%;" class=3D""><br style=3D"max-width: 100%;" =
class=3D""></li><li style=3D"max-width: 100%;" class=3D""><a =
href=3D"https://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2021-1252" =
rel=3D"nofollow" target=3D"_blank" style=3D"color: rgb(73, 129, 254); =
max-width: 100%;" class=3D"">CVE-2021-1252</a>: Fix for Excel XLM parser =
infinite loop. Affects 0.103.0 and 0.103.1 only.<br style=3D"max-width: =
100%;" class=3D""><br style=3D"max-width: 100%;" class=3D""></li><li =
style=3D"max-width: 100%;" class=3D""><a =
href=3D"https://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2021-1404" =
rel=3D"nofollow" target=3D"_blank" style=3D"color: rgb(73, 129, 254); =
max-width: 100%;" class=3D"">CVE-2021-1404</a>: Fix for PDF parser =
buffer over-read; possible crash. Affects 0.103.0 and 0.103.1 only.<br =
style=3D"max-width: 100%;" class=3D""><br style=3D"max-width: 100%;" =
class=3D""></li><li style=3D"max-width: 100%;" class=3D""><a =
href=3D"https://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2021-1405" =
rel=3D"nofollow" target=3D"_blank" style=3D"color: rgb(73, 129, 254); =
max-width: 100%;" class=3D"">CVE-2021-1405</a>: Fix for mail parser =
NULL-dereference crash. Affects 0.103.1 and prior.<br style=3D"max-width: =
100%;" class=3D""><br style=3D"max-width: 100%;" class=3D""></li><li =
style=3D"max-width: 100%;" class=3D"">Fix possible memory leak in PNG =
parser.<br style=3D"max-width: 100%;" class=3D""> <br style=3D"max-width: =
100%;" class=3D""></li><li style=3D"max-width: 100%;" class=3D"">Fix =
ClamOnAcc scan on file-creation race condition so files are scanned =
after their contents are written.<br style=3D"max-width: 100%;" =
class=3D""><br style=3D"max-width: 100%;" class=3D""></li><li =
style=3D"max-width: 100%;" class=3D"">FreshClam: Deprecate the <span =
style=3D"max-width: 100%;" class=3D"">SafeBrowsing</span> config option. =
The <span style=3D"max-width: 100%;" class=3D"">SafeBrowsing</span> =
option will no longer do anything.<br style=3D"max-width: 100%;" =
class=3D""><br style=3D"max-width: 100%;" class=3D"">For more details, =
see our <a =
href=3D"https://blog.clamav.net/2020/06/the-future-of-clamav-safebrowsing.=
html" style=3D"color: rgb(73, 129, 254); max-width: 100%;" class=3D"">blog=
 post from last year about the future of the ClamAV Safe Browsing =
database</a>.<i style=3D"max-width: 100%;" class=3D""><br =
style=3D"max-width: 100%;" class=3D""><br style=3D"max-width: 100%;" =
class=3D"">Tip</i>: If creating and hosting your own <span =
style=3D"max-width: 100%;" class=3D"">safebrowing.gdb</span> database, =
you can use the <span style=3D"max-width: 100%;" =
class=3D"">DatabaseCustomURL</span> option in <span style=3D"max-width: =
100%;" class=3D"">freshclam.conf</span> to download it.<br =
style=3D"max-width: 100%;" class=3D""> <br style=3D"max-width: 100%;" =
class=3D""></li><li style=3D"max-width: 100%;" class=3D"">FreshClam: =
Improved HTTP 304, 403, &amp; 429 handling.<br style=3D"max-width: =
100%;" class=3D""><br style=3D"max-width: 100%;" class=3D""></li><li =
style=3D"max-width: 100%;" class=3D"">FreshClam: Added back the <span =
style=3D"max-width: 100%;" class=3D"">mirrors.dat</span> file to the =
database directory.<br style=3D"max-width: 100%;" class=3D""><br =
style=3D"max-width: 100%;" class=3D"">This new <span style=3D"max-width: =
100%;" class=3D"">mirrors.dat</span> file will store:</li><ul =
style=3D"max-width: 100%;" class=3D""><li style=3D"max-width: 100%;" =
class=3D"">A randomly generated UUID for the FreshClam =
User-Agent.</li><li style=3D"max-width: 100%;" class=3D"">A retry-after =
timestamp that so FreshClam won't try to update after having received an =
HTTP 429 response until the Retry-After timeout has expired.<br =
style=3D"max-width: 100%;" class=3D""><br style=3D"max-width: 100%;" =
class=3D""></li></ul><li style=3D"max-width: 100%;" class=3D"">FreshClam =
will now exit with a failure in daemon mode if an HTTP 403 (Forbidden) =
was received, because retrying later won't help any. The FreshClam user =
will have to take actions to get unblocked.<br style=3D"max-width: =
100%;" class=3D""><br style=3D"max-width: 100%;" class=3D""></li><li =
style=3D"max-width: 100%;" class=3D"">Fix the FreshClam mirror-sync =
issue where a downloaded database is "older than the version =
advertised."<br style=3D"max-width: 100%;" class=3D""><br =
style=3D"max-width: 100%;" class=3D"">If a new CVD download gets a =
version that is older than advertised, FreshClam will keep the older =
version and retry the update so that the incremental update process =
(CDIFF patch process) will update to the latest version. <br =
style=3D"max-width: 100%;" class=3D""></li></ul>

</div>
<div style=3D"max-width: 100%;" class=3D"">

<div style=3D"max-width: 100%;" class=3D""><span style=3D"max-width: =
100%;" class=3D"">
Labels:
<a href=3D"https://blog.clamav.net/search/label/0.103.2" rel=3D"tag" =
style=3D"color: rgb(73, 129, 254); max-width: 100%;" =
class=3D"">0.103.2</a>,
<a href=3D"https://blog.clamav.net/search/label/clamav" rel=3D"tag" =
style=3D"color: rgb(73, 129, 254); max-width: 100%;" =
class=3D"">clamav</a>,
<a href=3D"https://blog.clamav.net/search/label/release" rel=3D"tag" =
style=3D"color: rgb(73, 129, 254); max-width: 100%;" =
class=3D"">release</a>
</span>
</div>

</div>
</div>

</div></div></div></div></div></blockquote></div></body></html>=

--Apple-Mail=_221300CE-70DB-4D88-BC62-3C819BB34050--

--Apple-Mail=_A92225D4-1087-475B-89CE-BECAC1B8B495
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment; filename="signature.asc"
Content-Type: application/pgp-signature;
	name=signature.asc
Content-Description: Message signed with OpenPGP

-----BEGIN PGP SIGNATURE-----

iF0EARECAB0WIQQnwPaXyuTcPH162gBdwY69d72oLgUCYG30iAAKCRBdwY69d72o
Ln/mAKCfD2zoschUk55IijV0H4HGswTMTgCfeOk6iGf/0+KTJk0Uorv+CXDk/9Y=
=7Zrf
-----END PGP SIGNATURE-----

--Apple-Mail=_A92225D4-1087-475B-89CE-BECAC1B8B495--

--===============7410036279193947545==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________

clamav-announce mailing list
[email protected]
https://lists.clamav.net/mailman/listinfo/clamav-announce

http://www.clamav.net/contact.html#ml

--===============7410036279193947545==--