New packages for ClamAV 0.103.7, 0.104.4, 0.105.1 to resolve CVE's
"Micah Snyder (micasnyd)" <[email protected]> Mon, 31 Oct 2022 20:08:07 +0000
| Newsgroups | gmane.comp.security.virus.clamav.announce |
|---|---|
| Message-ID | <BYAPR11MB31746BE2140C2BFE646454DBC6379__4987.50051935843$1667247661$gmane$org@BYAPR11MB3174.namprd11.prod.outlook.com> |
--===============4807461783824981226==
Content-Language: en-US
Content-Type: multipart/alternative;
boundary="_000_BYAPR11MB31746BE2140C2BFE646454DBC6379BYAPR11MB3174namp_"
--_000_BYAPR11MB31746BE2140C2BFE646454DBC6379BYAPR11MB3174namp_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
Read this announcement online at https://blog.clamav.net/2022/10/new-packag=
es-for-clamav-01037-01044.html
Today we are publishing updated packages for ClamAV 0.103.7, 0.104.4, and 0=
.105.1.
Why we updated the installer packages
The ClamAV RPM, DEB, PKG, MSI and ZIP installer packages come with all libr=
ary dependencies bundled. The updated installer packages resolve the follow=
ing CVE's:
* CVE-2022-37434<https://nvd.nist.gov/vuln/detail/CVE-2022-37434> - A c=
ritical severity vulnerability in the zlib library.
* CVE-2022-40303<https://nvd.nist.gov/vuln/detail/CVE-2022-40303> - A h=
igh severity vulnerability in the libxml2 library. Note: As of writing, the=
details of this CVE are not published. However, you can find additional de=
tails on other sites<https://www.suse.com/pt-br/security/cve/CVE-2022-40303=
.html>.
* CVE-2022-40304<https://nvd.nist.gov/vuln/detail/CVE-2022-40304> - A h=
igh severity vulnerability in the libxml2 library. Note: As of writing, the=
details of this CVE are not published. However, you can find additional de=
tails on other sites<https://www.suse.com/pt-br/security/cve/CVE-2022-40304=
.html>.
Why we updated the 0.105.1 source package
Starting with ClamAV 0.105.1, some of the ClamAV project is written in Rust=
and depends on Rust libraries. To make it possible for our users to build =
ClamAV offline, we bundle in the Rust dependencies.
There are no CVEs present for the Rust libraries bundled in the original 0.=
105.1 package. However, there are several critical bugs in the JPEG and TIF=
F image processing libraries in the original 0.105.1 source package. The kn=
own issues were resolved in image-tiff version 0.7.4<https://github.com/ima=
ge-rs/image-tiff/releases/tag/v0.7.4> and jpeg-decoder version 0.3.0<https:=
//github.com/image-rs/jpeg-decoder/releases/tag/v0.3.0>. The clamav-0.105.1=
-2.tar.gz source package includes the updated libraries.
Linux/Unix package maintainers are encouraged to publish new revisions of t=
heir own packages for ClamAV 0.105.1 to get these fixes. Anyone who built C=
lamAV from the original clamav-0.105.1.tar.gz source package is encouraged =
to reinstall from the newer source package.
Where to find the updated packages
The new packages have a "-2" suffix to indicate the package revision. For e=
xample, clamav-0.105.1-2.macos.universal.pkg is the updated package replaci=
ng clamav-0.105.1.macos.universal.pkg.
As always, you can get the updated packages from the ClamAV.net Downloads p=
age<https://www.clamav.net/downloads>. The original packages have been hidd=
en on the web page and replaced by the updated packages. If you need the or=
iginals, the URLs to download them still work.
What about the Docker images
The official ClamAV docker image has been updated to patch the zlib and lib=
xml2 vulnerabilities. The following tags have been updated to point to the =
new images:
* clamav/clamav:latest
* clamav/clamav:latest_base
* clamav/clamav:stable
* clamav/clamav:stable_base
* clamav/clamav:0.105
* clamav/clamav:0.105_base
* clamav/clamav:0.105.1
* clamav/clamav:0.105.1_base
Be sure to use docker pull to get the latest version of the image. For exam=
ple:
docker pull clamav/clamav:0.105_base
Posted by Micah Snyder<https://www.blogger.com/profile/07798916006145826441=
> at 3:15 PM<https://blog.clamav.net/2022/10/new-packages-for-clamav-01037-=
01044.html>[https://img1.blogblog.com/img/icon18_email.gif]<https://www.blo=
gger.com/email-post.g?blogID=3D2366689974368239573&postID=3D726866469608145=
9857>
Micah Snyder
ClamAV Development
Talos
Cisco Systems, Inc.
--_000_BYAPR11MB31746BE2140C2BFE646454DBC6379BYAPR11MB3174namp_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<style type=3D"text/css" style=3D"display:none;"> P {margin-top:0;margin-bo=
ttom:0;} </style>
</head>
<body dir=3D"ltr">
<font size=3D"2"><span style=3D"font-size:11pt" class=3D"elementToProof Con=
tentPasted1">Read this announcement online at
<a href=3D"https://blog.clamav.net/2022/10/new-packages-for-clamav-01037-01=
044.html" id=3D"LPNoLPOWALinkPreview">
https://blog.clamav.net/2022/10/new-packages-for-clamav-01037-01044.html</a=
><br>
</span></font>
<div class=3D"_Entity _EType_OWALinkPreview _EId_OWALinkPreview _EReadonly_=
1"></div>
<br>
<div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);" class=
=3D"elementToProof">
<div class=3D"post-body entry-content">
<p class=3D"code-line" data-line=3D"0" dir=3D"auto" style=3D"font-size:14px=
;margin-bottom:0.7em;margin-top:0px">
<span class=3D"ContentPasted0"><br>
</span></p>
<p class=3D"code-line" data-line=3D"0" dir=3D"auto" style=3D"font-size:14px=
;margin-bottom:0.7em;margin-top:0px">
<span class=3D"ContentPasted0">Today we are publishing updated packages for=
ClamAV 0.103.7, 0.104.4, and 0.105.1.</span></p>
<h4 class=3D"code-line" data-line=3D"2" style=3D"margin-bottom: 0.2em; marg=
in-top: 0px; text-align: left;">
<span class=3D"ContentPasted0">Why we updated the installer packages</span>=
</h4>
<p class=3D"code-line" data-line=3D"4" dir=3D"auto" style=3D"font-size:14px=
;margin-bottom:0.7em;margin-top:0px">
<span class=3D"ContentPasted0">The ClamAV RPM, DEB, PKG, MSI and ZIP instal=
ler packages come with all library dependencies bundled. The updated instal=
ler packages resolve the following CVE's:</span></p>
<ul class=3D"code-line" data-line=3D"5" dir=3D"auto" style=3D"font-size:14p=
x;margin-bottom:0.7em;margin-top:0px">
<li class=3D"code-line" data-line=3D"5" dir=3D"auto"><span><span style=3D"c=
olor:black" class=3D"ContentPasted0"><a data-href=3D"https://nvd.nist.gov/v=
uln/detail/CVE-2022-37434" href=3D"https://nvd.nist.gov/vuln/detail/CVE-202=
2-37434" title=3D"https://nvd.nist.gov/vuln/detail/CVE-2022-37434" class=3D=
"ContentPasted0">CVE-2022-37434</a><span class=3D"ContentPasted0"> </s=
pan>-
A critical severity vulnerability in the<span class=3D"ContentPasted0">&nb=
sp;</span><code style=3D"font-size:1em;line-height:1.357em" class=3D"Conten=
tPasted0">zlib</code><span class=3D"ContentPasted0"> </span>library.</=
span></span></li><li class=3D"code-line" data-line=3D"6" dir=3D"auto"><span=
><span style=3D"color:black" class=3D"ContentPasted0"><a data-href=3D"https=
://nvd.nist.gov/vuln/detail/CVE-2022-40303" href=3D"https://nvd.nist.gov/vu=
ln/detail/CVE-2022-40303" title=3D"https://nvd.nist.gov/vuln/detail/CVE-202=
2-40303" class=3D"ContentPasted0">CVE-2022-40303</a><span class=3D"ContentP=
asted0"> </span>-
A high severity vulnerability in the<span class=3D"ContentPasted0"> <=
/span><code style=3D"font-size:1em;line-height:1.357em" class=3D"ContentPas=
ted0">libxml2</code><span class=3D"ContentPasted0"> </span>library. No=
te: As of writing, the details of this CVE are not
published. However, you can find additional details<span class=3D"ContentP=
asted0"> </span><a data-href=3D"https://www.suse.com/pt-br/security/cv=
e/CVE-2022-40303.html" href=3D"https://www.suse.com/pt-br/security/cve/CVE-=
2022-40303.html" title=3D"https://www.suse.com/pt-br/security/cve/CVE-2022-=
40303.html" class=3D"ContentPasted0">on
other sites</a>.</span></span></li><li class=3D"code-line" data-line=3D"7"=
dir=3D"auto"><span><span style=3D"color:black" class=3D"ContentPasted0"><a=
data-href=3D"https://nvd.nist.gov/vuln/detail/CVE-2022-40304" href=3D"http=
s://nvd.nist.gov/vuln/detail/CVE-2022-40304" title=3D"https://nvd.nist.gov/=
vuln/detail/CVE-2022-40304" class=3D"ContentPasted0">CVE-2022-40304</a><spa=
n class=3D"ContentPasted0"> </span>-
A high severity vulnerability in the<span class=3D"ContentPasted0"> <=
/span><code style=3D"font-size:1em;line-height:1.357em" class=3D"ContentPas=
ted0">libxml2</code><span class=3D"ContentPasted0"> </span>library. No=
te: As of writing, the details of this CVE are not
published. However, you can find additional details<span class=3D"ContentP=
asted0"> </span><a data-href=3D"https://www.suse.com/pt-br/security/cv=
e/CVE-2022-40304.html" href=3D"https://www.suse.com/pt-br/security/cve/CVE-=
2022-40304.html" title=3D"https://www.suse.com/pt-br/security/cve/CVE-2022-=
40304.html" class=3D"ContentPasted0">on
other sites</a>.</span></span></li></ul>
<div><span style=3D"font-size:14px"><br class=3D"ContentPasted0">
</span></div>
<h4 class=3D"code-line" data-line=3D"9" style=3D"margin-bottom: 0.2em; marg=
in-top: 0px; text-align: left;">
<span class=3D"ContentPasted0">Why we updated the 0.105.1 source package</s=
pan></h4>
<p class=3D"code-line" data-line=3D"11" dir=3D"auto" style=3D"font-size:14p=
x;margin-bottom:0.7em;margin-top:0px">
<span class=3D"ContentPasted0">Starting with ClamAV 0.105.1, some of the Cl=
amAV project is written in Rust and depends on Rust libraries. To make it p=
ossible for our users to build ClamAV offline, we bundle in the Rust depend=
encies.</span></p>
<p class=3D"code-line" data-line=3D"13" dir=3D"auto" style=3D"font-size:14p=
x;margin-bottom:0.7em;margin-top:0px">
<span class=3D"ContentPasted0">There are no CVEs present for the Rust libra=
ries bundled in the original 0.105.1 package. However, there are several cr=
itical bugs in the JPEG and TIFF image processing libraries in the original=
0.105.1 source package. The known
issues were resolved in<span class=3D"ContentPasted0"> </span><span s=
tyle=3D"color:black" class=3D"ContentPasted0"><a data-href=3D"https://githu=
b.com/image-rs/image-tiff/releases/tag/v0.7.4" href=3D"https://github.com/i=
mage-rs/image-tiff/releases/tag/v0.7.4" title=3D"https://github.com/image-r=
s/image-tiff/releases/tag/v0.7.4" class=3D"ContentPasted0"><code style=3D"f=
ont-size:1em;line-height:1.357em">image-tiff</code><span> </span>versi=
on
0.7.4</a><span class=3D"ContentPasted0"> </span>and<span class=3D"Con=
tentPasted0"> </span><a data-href=3D"https://github.com/image-rs/jpeg-=
decoder/releases/tag/v0.3.0" href=3D"https://github.com/image-rs/jpeg-decod=
er/releases/tag/v0.3.0" title=3D"https://github.com/image-rs/jpeg-decoder/r=
eleases/tag/v0.3.0" class=3D"ContentPasted0"><code style=3D"font-size:1em;l=
ine-height:1.357em">jpeg-decoder</code><span> </span>version
0.3.0</a>. The<span class=3D"ContentPasted0"> </span><code style=3D"f=
ont-size:1em;line-height:1.357em" class=3D"ContentPasted0">clamav-0.105.1-2=
.tar.gz</code><span class=3D"ContentPasted0"> </span>source package in=
cludes the updated libraries.</span></span></p>
<p class=3D"code-line" data-line=3D"15" dir=3D"auto" style=3D"font-size:14p=
x;margin-bottom:0.7em;margin-top:0px">
<span class=3D"ContentPasted0">Linux/Unix package maintainers are encourage=
d to publish new revisions of their own packages for ClamAV 0.105.1 to get =
these fixes. Anyone who built ClamAV from the original<span class=3D"Conten=
tPasted0"> </span><code style=3D"font-size:1em;line-height:1.357em" cl=
ass=3D"ContentPasted0">clamav-0.105.1.tar.gz</code><span class=3D"ContentPa=
sted0"> </span>source
package is encouraged to reinstall from the newer source package.</span></=
p>
<p class=3D"code-line" data-line=3D"15" dir=3D"auto" style=3D"font-size:14p=
x;margin-bottom:0.7em;margin-top:0px">
<span><br class=3D"ContentPasted0">
</span></p>
<h4 class=3D"code-line" data-line=3D"17" style=3D"margin-bottom: 0.2em; mar=
gin-top: 0px; text-align: left;">
<span class=3D"ContentPasted0">Where to find the updated packages</span></h=
4>
<p class=3D"code-line" data-line=3D"19" dir=3D"auto" style=3D"font-size:14p=
x;margin-bottom:0.7em;margin-top:0px">
<span class=3D"ContentPasted0">The new packages have a<span class=3D"Conten=
tPasted0"> "</span><code style=3D"font-size:1em;line-height:1.357em" c=
lass=3D"ContentPasted0">-2"</code><span class=3D"ContentPasted0">
</span>suffix to indicate the package revision. For example,<span class=3D"=
ContentPasted0"> </span><code style=3D"font-size:1em;line-height:1.357=
em" class=3D"ContentPasted0">clamav-0.105.1-2.macos.universal.pkg</code><sp=
an class=3D"ContentPasted0"> </span>is the updated
package replacing<span class=3D"ContentPasted0"> </span><code style=
=3D"font-size:1em;line-height:1.357em" class=3D"ContentPasted0">clamav-0.10=
5.1.macos.universal.pkg</code>.</span></p>
<p class=3D"code-line" data-line=3D"21" dir=3D"auto" style=3D"font-size:14p=
x;margin-bottom:0.7em;margin-top:0px">
<span class=3D"ContentPasted0">As always, you can get the updated packages =
from<span class=3D"ContentPasted0"> </span><span style=3D"color:black"=
class=3D"ContentPasted0"><a data-href=3D"https://www.clamav.net/downloads"=
href=3D"https://www.clamav.net/downloads" title=3D"https://www.clamav.net/=
downloads" class=3D"ContentPasted0">the
ClamAV.net Downloads page</a>. The original packages have been hidden on t=
he web page and replaced by the updated packages. If you need the originals=
, the URLs to download them still work.</span></span></p>
<p class=3D"code-line" data-line=3D"21" dir=3D"auto" style=3D"font-size:14p=
x;margin-bottom:0.7em;margin-top:0px">
<span><span style=3D"color:black"><br class=3D"ContentPasted0">
</span></span></p>
<h4 class=3D"code-line" data-line=3D"23" style=3D"font-weight:normal;margin=
-bottom:0.2em;margin-top:0px;text-align:left">
<span class=3D"ContentPasted0">What about the Docker images</span></h4>
<p class=3D"code-line" data-line=3D"25" dir=3D"auto" style=3D"font-size:14p=
x;margin-bottom:0.7em;margin-top:0px">
<span class=3D"ContentPasted0">The official ClamAV docker image has been up=
dated to patch the<span class=3D"ContentPasted0"> </span><code style=
=3D"font-size:1em;line-height:1.357em" class=3D"ContentPasted0">zlib</code>=
<span class=3D"ContentPasted0"> </span>and<span class=3D"ContentPasted=
0"> </span><code style=3D"font-size:1em;line-height:1.357em" class=3D"=
ContentPasted0">libxml2</code><span class=3D"ContentPasted0"> </span>v=
ulnerabilities.
The following tags have been updated to point to the new images:</span></p=
>
<ul class=3D"code-line" data-line=3D"26" dir=3D"auto" style=3D"font-size:14=
px;margin-bottom:0.7em;margin-top:0px">
<li class=3D"code-line" data-line=3D"26" dir=3D"auto"><span><code style=3D"=
font-size:1em;line-height:1.357em" class=3D"ContentPasted0">clamav/clamav:l=
atest</code></span></li><li class=3D"code-line" data-line=3D"27" dir=3D"aut=
o"><span><code style=3D"font-size:1em;line-height:1.357em" class=3D"Content=
Pasted0">clamav/clamav:latest_base</code></span></li><li class=3D"code-line=
" data-line=3D"28" dir=3D"auto"><span><code style=3D"font-size:1em;line-hei=
ght:1.357em" class=3D"ContentPasted0">clamav/clamav:stable</code></span></l=
i><li class=3D"code-line" data-line=3D"29" dir=3D"auto"><span><code style=
=3D"font-size:1em;line-height:1.357em" class=3D"ContentPasted0">clamav/clam=
av:stable_base</code></span></li><li class=3D"code-line" data-line=3D"30" d=
ir=3D"auto"><span><code style=3D"font-size:1em;line-height:1.357em" class=
=3D"ContentPasted0">clamav/clamav:0.105</code></span></li><li class=3D"code=
-line" data-line=3D"31" dir=3D"auto"><span><code style=3D"font-size:1em;lin=
e-height:1.357em" class=3D"ContentPasted0">clamav/clamav:0.105_base</code><=
/span></li><li class=3D"code-line" data-line=3D"32" dir=3D"auto"><span><cod=
e style=3D"font-size:1em;line-height:1.357em" class=3D"ContentPasted0">clam=
av/clamav:0.105.1</code></span></li><li class=3D"code-line" data-line=3D"33=
" dir=3D"auto"><span><code style=3D"font-size:1em;line-height:1.357em" clas=
s=3D"ContentPasted0">clamav/clamav:0.105.1_base</code></span></li></ul>
<p class=3D"code-line" data-line=3D"35" dir=3D"auto" style=3D"font-size:14p=
x;margin-bottom:0.7em;margin-top:0px">
<span class=3D"ContentPasted0">Be sure to use<span class=3D"ContentPasted0"=
> </span><code style=3D"font-size:1em;line-height:1.357em" class=3D"Co=
ntentPasted0">docker pull</code><span class=3D"ContentPasted0"> </span=
>to get the latest version of the image. For example:</span></p>
<pre class=3D"code-active-line" style=3D"background-color:rgba(10, 10, 10, =
0.4);border-radius:3px;font-size:14px;margin-top:0px;overflow:auto;padding:=
16px"><span><code class=3D"code-line language-sh" data-line=3D"36" dir=3D"a=
uto" style=3D"font-size:1em;line-height:1.357em;tab-size:4"><div class=3D"C=
ontentPasted0">docker pull clamav/clamav:0.105_base</div></code></span></pr=
e>
<div style=3D"clear:both"></div>
</div>
<div class=3D"post-footer">
<div class=3D"post-footer-line post-footer-line-1"><span class=3D"post-auth=
or vcard ContentPasted0">Posted by
<span class=3D"fn"><a class=3D"g-profile ContentPasted0" href=3D"https://ww=
w.blogger.com/profile/07798916006145826441" rel=3D"author" title=3D"author =
profile"><span>Micah Snyder</span></a></span></span><span class=3D"post-tim=
estamp ContentPasted0"> at
<a class=3D"timestamp-link ContentPasted0" href=3D"https://blog.clamav.net/=
2022/10/new-packages-for-clamav-01037-01044.html" rel=3D"bookmark" title=3D=
"permanent link">
<abbr class=3D"published" title=3D"2022-10-31T15:15:00-04:00">3:15 PM</abbr=
></a></span><span class=3D"post-comment-link"></span><span class=3D"post-ic=
ons"><span class=3D"item-action"><a href=3D"https://www.blogger.com/email-p=
ost.g?blogID=3D2366689974368239573&postID=3D7268664696081459857" title=
=3D"Email Post" class=3D"ContentPasted0"><img alt=3D"" class=3D"icon-action=
" width=3D"18" height=3D"13" src=3D"https://img1.blogblog.com/img/icon18_em=
ail.gif"></a><br>
</span></span></div>
<div class=3D"post-footer-line post-footer-line-1"><span class=3D"post-icon=
s"><span class=3D"item-action"><br>
</span></span></div>
</div>
<br>
</div>
<div class=3D"elementToProof">
<div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id=3D"Signature">
<div>
<div style=3D"font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12p=
t; color:rgb(0,0,0)">
<br style=3D"font-family:Helvetica; font-size:12px; font-weight:normal; orp=
hans:auto; text-align:start; widows:auto">
<span style=3D"font-family:Helvetica; font-size:12px; font-weight:normal; o=
rphans:auto; text-align:start; widows:auto; display:inline!important">Micah=
Snyder</span><br style=3D"font-family:Helvetica; font-size:12px; font-weig=
ht:normal; orphans:auto; text-align:start; widows:auto">
<span style=3D"font-family:Helvetica; font-size:12px; font-weight:normal; o=
rphans:auto; text-align:start; widows:auto; display:inline!important">ClamA=
V Development</span><br style=3D"font-family:Helvetica; font-size:12px; fon=
t-weight:normal; orphans:auto; text-align:start; widows:auto">
<span style=3D"font-family:Helvetica; font-size:12px; font-weight:normal; o=
rphans:auto; text-align:start; widows:auto; display:inline!important">Talos=
</span><br style=3D"font-family:Helvetica; font-size:12px; font-weight:norm=
al; orphans:auto; text-align:start; widows:auto">
<span style=3D"font-family:Helvetica; font-size:12px; font-weight:normal; o=
rphans:auto; text-align:start; widows:auto; display:inline!important">Cisco=
Systems, Inc.</span><br>
</div>
</div>
</div>
</div>
</body>
</html>
--_000_BYAPR11MB31746BE2140C2BFE646454DBC6379BYAPR11MB3174namp_--
--===============4807461783824981226==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
clamav-announce mailing list
[email protected]
https://lists.clamav.net/mailman/listinfo/clamav-announce
http://www.clamav.net/contact.html#ml
--===============4807461783824981226==--