ClamAV 0.103.5 and 0.104.2 security patch release; 0.102 past EOL
"Micah Snyder (micasnyd)" <[email protected]> Wed, 12 Jan 2022 20:12:42 +0000
| Newsgroups | gmane.comp.security.virus.clamav.announce |
|---|---|
| Message-ID | <BYAPR11MB317442D6EB9157BEB9C4E703C6529__12339.1246468358$1642018659$gmane$org@BYAPR11MB3174.namprd11.prod.outlook.com> |
--===============5511975143973305184==
Content-Language: en-US
Content-Type: multipart/alternative;
boundary="_000_BYAPR11MB317442D6EB9157BEB9C4E703C6529BYAPR11MB3174namp_"
--_000_BYAPR11MB317442D6EB9157BEB9C4E703C6529BYAPR11MB3174namp_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
Find this announcement online at: https://blog.clamav.net/2022/01/clamav-01=
035-and-01042-security-patch.html
ClamAV versions 0.103.5 and 0.104.2 are now available for download on the c=
lamav.net Downloads page<https://www.clamav.net/downloads>.
We would also like to take this opportunity to remind users that versions 0=
.102 and 0.101 have reached their end-of-life period. These versions exceed=
ed our EOL dates on Jan. 3, 2022 and will soon be actively blocked from dow=
nloading signature database updates.
For additional details about ClamAV's end-of-life policy, please see our on=
line documentation<https://docs.clamav.net/faq/faq-eol.html>.
0.103.5
ClamAV 0.103.5 is a critical patch release with the following fixes:
* CVE-2022-20698<https://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2=
022-20698>: Fix for invalid pointer read that may cause a crash. This issue=
affects 0.104.1, 0.103.4 and prior when ClamAV is compiled with libjson-c =
and the CL_SCAN_GENERAL_COLLECT_METADATA scan option (the clamscan --gen-js=
on option) is enabled.
Cisco would like to thank Laurent Delosieres of ManoMano for reporting this=
vulnerability.
* Fixed ability to disable the file size limit with libclamav C API, li=
ke this:
cl_engine_set_num(engine, CL_ENGINE_MAX_FILESIZE, 0);
This issue didn't affect ClamD or ClamScan which also can disable the limit=
by setting it to zero using MaxFileSize 0 in clamd.conf for ClamD, or clam=
scan --max-filesize=3D0 for ClamScan.
Note: Internally, the max file size is still set to 2 GiB. Disabling the li=
mit for a scan will fall back on the internal 2 GiB limitation.
* Increased the maximum line length for ClamAV config files from 512 by=
tes to 1,024 bytes to allow for longer config option strings.
* SigTool: Fix insufficient buffer size for --list-sigs that caused a f=
ailure when listing a database containing one or more very long signatures.=
This fix was backported from 0.104.
Special thanks to the following for code contributions and bug reports:
* Laurent Delosieres
0.104.2
ClamAV 0.104.2 is a critical patch release with the following fixes:
* CVE-2022-20698<https://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2=
022-20698>: Fix for invalid pointer read that may cause a crash. Affects 0.=
104.1, 0.103.4 and prior when ClamAV is compiled with libjson-c and the CL_=
SCAN_GENERAL_COLLECT_METADATA scan option (the clamscan --gen-json option) =
is enabled.
Cisco would like to thank Laurent Delosieres of ManoMano for reporting this=
vulnerability.
* Fixed ability to disable the file size limit with libclamav C API, li=
ke this:
cl_engine_set_num(engine, CL_ENGINE_MAX_FILESIZE, 0);
This issue didn't impact ClamD or ClamScan which also can disable the limit=
by setting it to zero using MaxFileSize 0 in clamd.conf for ClamD, or clam=
scan --max-filesize=3D0 for ClamScan.
Note: Internally, the max file size is still set to 2 GiB. Disabling the li=
mit for a scan will fall back on the internal 2 GiB limitation.
* Increased the maximum line length for ClamAV config files from 512 by=
tes to 1,024 bytes to allow for longer config option strings.
Special thanks to the following for code contributions and bug reports:
* Laurent Delosieres
Micah Snyder
ClamAV Development
Talos
Cisco Systems, Inc.
--_000_BYAPR11MB317442D6EB9157BEB9C4E703C6529BYAPR11MB3174namp_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<style type=3D"text/css" style=3D"display:none;"> P {margin-top:0;margin-bo=
ttom:0;} </style>
</head>
<body dir=3D"ltr">
<div>
<div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0); --darkreader-inline-color: #e8e6e3;" data-dark=
reader-inline-color=3D"">
<h3>
<div><span style=3D"font-weight: normal; font-size: 12pt;">Find this announ=
cement online at:
<a href=3D"https://blog.clamav.net/2022/01/clamav-01035-and-01042-security-=
patch.html" id=3D"LPNoLPOWALinkPreview">
https://blog.clamav.net/2022/01/clamav-01035-and-01042-security-patch.html<=
/a><br>
</span></div>
</h3>
<div>
<p><br>
</p>
<p>ClamAV versions 0.103.5 and 0.104.2 are now available for download on th=
e <a href=3D"https://www.clamav.net/downloads" rel=3D"nofollow" target=3D"_=
blank">
clamav.net Downloads page</a>. </p>
<p><br>
</p>
<p>We would also like to take this opportunity to remind users that version=
s 0.102 and 0.101 have reached their end-of-life period. <b>These vers=
ions exceeded our EOL dates on Jan. 3, 2022 and will soon be actively block=
ed from downloading signature database
updates.</b></p>
<p><br>
</p>
<p>For additional details about ClamAV's end-of-life policy, <a href=3D"htt=
ps://docs.clamav.net/faq/faq-eol.html" rel=3D"nofollow" target=3D"_blank">
please see our online documentation</a>.</p>
<span><a></a></span>
<p><br>
</p>
<h2 data-sourcepos=3D"6:1-6:10" dir=3D"auto">0.103.5</h2>
<p data-sourcepos=3D"8:1-8:68" dir=3D"auto">ClamAV 0.103.5 is a critical pa=
tch release with the following fixes:</p>
<ul data-sourcepos=3D"10:1-36:0" dir=3D"auto">
<li data-sourcepos=3D"10:1-18:0">
<p data-sourcepos=3D"10:3-14:21"><a href=3D"https://cve.mitre.org/cgi-bin/c=
vename.cgi?name=3DCVE-2022-20698" rel=3D"nofollow noreferrer noopener" targ=
et=3D"_blank">CVE-2022-20698</a>: Fix for invalid pointer read that may cau=
se a crash. This issue affects 0.104.1, 0.103.4
and prior when ClamAV is compiled with libjson-c and the <code>CL_SCAN_GEN=
ERAL_COLLECT_METADATA</code> scan option (the
<code>clamscan --gen-json</code> option) is enabled.</p>
<p data-sourcepos=3D"16:3-17:16">Cisco would like to thank Laurent Delosier=
es of ManoMano for reporting this vulnerability.</p>
</li><li data-sourcepos=3D"19:1-29:0">
<p data-sourcepos=3D"19:3-19:79">Fixed ability to disable the file size lim=
it with libclamav C API, like this:</p>
<pre lang=3D"c"><code><span lang=3D"c"> <span>cl_engine_set_num</span=
><span>(</span><span>engine</span><span>,</span> <span>CL_ENGINE_MAX_F=
ILESIZE</span><span>,</span> <span>0</span><span>);</span></span></cod=
e></pre>
<p data-sourcepos=3D"23:3-25:43">This issue didn't affect ClamD or ClamScan=
which also can disable the limit by setting it to zero using
<code>MaxFileSize 0</code> in <code>clamd.conf</code> for ClamD, or <code>c=
lamscan --max-filesize=3D0</code> for ClamScan.</p>
<p data-sourcepos=3D"27:3-28:61">Note: Internally, the max file size is sti=
ll set to 2 GiB. Disabling the limit for a scan will fall back on the inter=
nal 2 GiB limitation.</p>
</li><li data-sourcepos=3D"30:1-32:0">
<p data-sourcepos=3D"30:3-31:55">Increased the maximum line length for Clam=
AV config files from 512 bytes to 1,024 bytes to allow for longer config op=
tion strings.</p>
</li><li data-sourcepos=3D"33:1-36:0">
<p data-sourcepos=3D"33:3-35:37">SigTool: Fix insufficient buffer size for =
<code>--list-sigs</code> that caused a failure when listing a database cont=
aining one or more very long signatures. This fix was backported from 0.104=
.</p>
</li></ul>
<p data-sourcepos=3D"37:1-37:71" dir=3D"auto">Special thanks to the followi=
ng for code contributions and bug reports:</p>
<ul data-sourcepos=3D"38:1-39:0" dir=3D"auto">
<li data-sourcepos=3D"38:1-39:0">Laurent Delosieres</li></ul>
<h2 data-sourcepos=3D"6:1-6:10" dir=3D"auto">0.104.2</h2>
<p data-sourcepos=3D"8:1-8:68" dir=3D"auto">ClamAV 0.104.2 is a critical pa=
tch release with the following fixes:</p>
<ul data-sourcepos=3D"10:1-32:0" dir=3D"auto">
<li data-sourcepos=3D"10:1-18:0">
<p data-sourcepos=3D"10:3-14:21"><a href=3D"https://cve.mitre.org/cgi-bin/c=
vename.cgi?name=3DCVE-2022-20698" rel=3D"nofollow noreferrer noopener" targ=
et=3D"_blank">CVE-2022-20698</a>: Fix for invalid pointer read that may cau=
se a crash. Affects 0.104.1, 0.103.4 and prior
when ClamAV is compiled with libjson-c and the <code>CL_SCAN_GENERAL_COLLE=
CT_METADATA</code> scan option (the
<code>clamscan --gen-json</code> option) is enabled.</p>
<p data-sourcepos=3D"16:3-17:16">Cisco would like to thank Laurent Delosier=
es of ManoMano for reporting this vulnerability.</p>
</li><li data-sourcepos=3D"19:1-29:0">
<p data-sourcepos=3D"19:3-19:79">Fixed ability to disable the file size lim=
it with libclamav C API, like this:</p>
<pre lang=3D"c"><code><span lang=3D"c"> <span>cl_engine_set_num</span=
><span>(</span><span>engine</span><span>,</span> <span>CL_ENGINE_MAX_F=
ILESIZE</span><span>,</span> <span>0</span><span>);</span></span></cod=
e></pre>
<p data-sourcepos=3D"23:3-25:43">This issue didn't impact ClamD or ClamScan=
which also can disable the limit by setting it to zero using
<code>MaxFileSize 0</code> in <code>clamd.conf</code> for ClamD, or <code>c=
lamscan --max-filesize=3D0</code> for ClamScan.</p>
<p data-sourcepos=3D"27:3-28:61">Note: Internally, the max file size is sti=
ll set to 2 GiB. Disabling the limit for a scan will fall back on the inter=
nal 2 GiB limitation.</p>
</li><li data-sourcepos=3D"30:1-32:0">
<p data-sourcepos=3D"30:3-31:55">Increased the maximum line length for Clam=
AV config files from 512 bytes to 1,024 bytes to allow for longer config op=
tion strings.</p>
</li></ul>
<p data-sourcepos=3D"33:1-33:71" dir=3D"auto">Special thanks to the followi=
ng for code contributions and bug reports:</p>
<ul data-sourcepos=3D"34:1-35:0" dir=3D"auto">
<li data-sourcepos=3D"34:1-35:0">Laurent Delosieres</li></ul>
<div style=3D"clear:both"></div>
</div>
<br>
</div>
<div id=3D"Signature">
<div>
<div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0); --darkreader-inline-color: #e8e6e3;" data-dark=
reader-inline-color=3D"">
<br style=3D"font-family:Helvetica; font-size:12px; font-weight:normal; orp=
hans:auto; text-align:start; widows:auto">
<span style=3D"font-family:Helvetica; font-size:12px; font-weight:normal; o=
rphans:auto; text-align:start; widows:auto; display:inline!important">Micah=
Snyder</span><br style=3D"font-family:Helvetica; font-size:12px; font-weig=
ht:normal; orphans:auto; text-align:start; widows:auto">
<span style=3D"font-family:Helvetica; font-size:12px; font-weight:normal; o=
rphans:auto; text-align:start; widows:auto; display:inline!important">ClamA=
V Development</span><br style=3D"font-family:Helvetica; font-size:12px; fon=
t-weight:normal; orphans:auto; text-align:start; widows:auto">
<span style=3D"font-family:Helvetica; font-size:12px; font-weight:normal; o=
rphans:auto; text-align:start; widows:auto; display:inline!important">Talos=
</span><br style=3D"font-family:Helvetica; font-size:12px; font-weight:norm=
al; orphans:auto; text-align:start; widows:auto">
<span style=3D"font-family:Helvetica; font-size:12px; font-weight:normal; o=
rphans:auto; text-align:start; widows:auto; display:inline!important">Cisco=
Systems, Inc.</span><br>
</div>
</div>
</div>
</div>
</body>
</html>
--_000_BYAPR11MB317442D6EB9157BEB9C4E703C6529BYAPR11MB3174namp_--
--===============5511975143973305184==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
clamav-announce mailing list
[email protected]
https://lists.clamav.net/mailman/listinfo/clamav-announce
http://www.clamav.net/contact.html#ml
--===============5511975143973305184==--