ClamAV 1.5.0 release candidate
"Val Snyder \(micasnyd\) via clamav-announce" <[email protected]> Wed, 20 Aug 2025 18:21:53 +0000
| Newsgroups | gmane.comp.security.virus.clamav.announce |
|---|---|
| Message-ID | <CH3PR11MB8750A6128542C2A00A343393C633A__22965.2085503162$1755714407$gmane$org@CH3PR11MB8750.namprd11.prod.outlook.com> |
--===============5516589023394447032==
Content-Language: en-US
Content-Type: multipart/alternative;
boundary="_000_CH3PR11MB8750A6128542C2A00A343393C633ACH3PR11MB8750namp_"
--_000_CH3PR11MB8750A6128542C2A00A343393C633ACH3PR11MB8750namp_
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable
Read this online at https://blog.clamav.net/2025/08/clamav-150-release-cand=
idate-now.html
The ClamAV 1.5.0 release candidate is now available. You may find the sourc=
e code and installers for this release at clamav.net/downloads<https://www.=
clamav.net/downloads> or on the ClamAV GitHub release page<https://github.c=
om/Cisco-Talos/clamav/releases/tag/clamav-1.5.0-rc>.
The release candidate phase is expected to last two to four weeks before we=
publish the stable release. This will depend on whether any changes are re=
quired to stabilize this version. Please take this time to evaluate ClamAV =
1.5.0.
Please help us validate this release by providing feedback via GitHub issue=
s<https://github.com/Cisco-Talos/clamav/issues>, via the ClamAV mailing lis=
t<https://lists.clamav.net/mailman/listinfo/clamav-users> or on our Discord=
<https://discord.gg/sGaxA5Q>.
IMPORTANT: A major feature of the 1.5 release is a FIPS-compliant method fo=
r verifying the authenticity of CVD signature database archives and CDIFF s=
ignature database patch files. The feature is ready to test in this release=
candidate, but we are not yet distributing the associated =93.cvd.sign=94 =
signature files for the daily, main, and bytecode databases. Because these =
files are not available, ClamAV will fall back to using the legacy MD5-base=
d RSA signature check. In other words, Freshclam will continue to fail on F=
IPS-enabled systems for now. However, the unit tests do include a test sign=
ing key and certificate pair along with tests to exercise signing and verif=
ication using the FIPS-compliant method.
Note: Windows builds on GitHub Actions, which use VCPkg to provide C librar=
y dependencies, are failing at this time.
Tip: If you are downloading the source from the GitHub release page, the pa=
ckage labeled "clamav-1.5.0-release candidate.tar.gz" does not require an i=
nternet connection to build. All dependencies are included in this package.=
However, if you download the ZIP or TAR.GZ generated by GitHub, located at=
the very bottom, then an internet connection will be required during the b=
uild to download additional Rust dependencies.
For Docker users, there is no specific Docker tag for the release candidate=
, but you can use the clamav:unstable or clamav:unstable_base tags.
ClamAV 1.5.0 includes the following improvements and changes:
Major changes
*
Added checks to determine if an OLE2-based Microsoft Office document is enc=
rypted.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1295>
*
Added the ability to record URIs found in HTML if the generate-JSON-metadat=
a feature is enabled. Also adds an option to disable this in case you want =
the JSON metadata feature but do not want to record HTML URIs. The ClamScan=
command-line option is --json-store-html-uris=3Dno. The clamd.conf config =
option is JsonStoreHTMLURIs no. The libclamav general scan option is CL_SCA=
N_GENERAL_STORE_HTML_URIS
GitHub pull request #1<https://github.com/Cisco-Talos/clamav/pull/1281>
GitHub pull request #2<https://github.com/Cisco-Talos/clamav/pull/1482>
GitHub pull request #3<https://github.com/Cisco-Talos/clamav/pull/1514>
*
Added the ability to record URIs found in PDFs if the generate-JSON-metadat=
a feature is enabled. Also adds an option to disable this in case you want =
the JSON metadata feature but do not want to record PDF URIs. The ClamScan =
command-line option is --json-store-pdf-uris=3Dno. The clamd.conf config op=
tion is JsonStorePDFURIs no. The libclamav general scan option is CL_SCAN_G=
ENERAL_STORE_PDF_URIS
GitHub pull request #1<https://github.com/Cisco-Talos/clamav/pull/1482>
GitHub pull request #2<https://github.com/Cisco-Talos/clamav/pull/1514>
*
Added regex support for the clamd.conf OnAccessExcludePath config option. T=
his change courtesy of GitHub user b1tg.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1314>
*
Added CVD signing/verification with external .sign files.
Freshclam will now attempt to download external signature files to accompan=
y existing .cvd databases and .cdiff patch files. Sigtool now has commands =
to sign and verify using the external signatures.
ClamAV now installs a 'certs' directory in the app config directory (e.g., =
<prefix>/etc/certs). The install path is configurable. The CMake option to =
configure the CVD certs directory is -D CVD_CERTS_DIRECTORY=3DPATH
New options to set an alternative CVD certs directory:
Added two new APIs to the public clamav.h header:
cl_error_t cl_cvdverify_ex(
const char *file,
const char *certs_directory,
uint32_t dboptions);
cl_error_t cl_cvdunpack_ex(
const char *file,
const char *dir,
const char *certs_directory,
uint32_t dboptions);
The original cl_cvdverify and cl_cvdunpack are deprecated.
Added a cl_engine_field enum option CL_ENGINE_CVDCERTSDIR. You may set this=
option with cl_engine_set_str and get it with cl_engine_get_str, to overri=
de the compiled in default CVD certs directory.
Thank you to Mark Carey at SAP for inspiring work on this feature with an i=
nitial proof of concept for external-signature FIPS compliant CVD signing.
GitHub pull request #1<https://github.com/Cisco-Talos/clamav/pull/1417>
GitHub pull request #2<https://github.com/Cisco-Talos/clamav/pull/1478>
GitHub pull request #3<https://github.com/Cisco-Talos/clamav/pull/1489>
GitHub pull request #4<https://github.com/Cisco-Talos/clamav/pull/1491>
* The command-line option for Freshclam, ClamD, ClamScan, and Sigtoo=
l is --cvdcertsdir PATH
* The environment variable for Freshclam, ClamD, ClamScan, and Sigto=
ol is CVD_CERTS_DIR
* The config option for Freshclam and ClamD is CVDCertsDirectory PAT=
H
*
Freshclam, ClamD, ClamScan, and Sigtool: Added an option to enable FIPS-lik=
e limits disabling MD5 and SHA1 from being used for verifying digital signa=
tures or for being used to trust a file when checking for false positives (=
FPs).
For freshclam.conf and clamd.conf set this config option:
FIPSCryptoHashLimits yes
For clamscan and sigtool use this command-line option:
--fips-limits
For libclamav: Enable FIPS-limits for a ClamAV engine like this:
cl_engine_set_num(engine, CL_ENGINE_FIPS_LIMITS, 1);
ClamAV will also attempt to detect if FIPS-mode is enabled. If so, it will =
automatically enable the FIPS-limits feature.
This change mitigates safety concerns over the use of MD5 and SHA1 algorith=
ms to trust files and is required to enable ClamAV to operate legitimately =
in FIPS-mode enabled environments.
Note: ClamAV may still calculate MD5 or SHA1 hashes as needed for detection=
purposes or for informational purposes in FIPS-enabled environments and wh=
en the FIPS-limits option is enabled.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
*
Upgraded the clean-file scan cache to use SHA2-256 (prior versions use MD5)=
. The clean-file cache algorithm is not configurable.
This change resolves safety concerns over the use of MD5 to trust files and=
is required to enable ClamAV to operate legitimately in FIPS-mode enabled =
environments.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
*
ClamD: Added an option to disable select administrative commands including =
SHUTDOWN, RELOAD, STATS and VERSION.
The new clamd.conf options are:
EnableShutdownCommand yes
EnableReloadCommand yes
EnableStatsCommand yes
EnableVersionCommand yes
This change courtesy of GitHub user ChaoticByte.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1502>
*
libclamav: Added extended hashing functions with a "flags" parameter that a=
llows the caller to choose if they want to bypass FIPS hash algorithm limit=
s:
cl_error_t cl_hash_data_ex(
const char *alg,
const uint8_t *data,
size_t data_len,
uint8_t **hash,
size_t *hash_len,
uint32_t flags);
cl_error_t cl_hash_init_ex(
const char *alg,
uint32_t flags,
cl_hash_ctx_t **ctx_out);
cl_error_t cl_update_hash_ex(
cl_hash_ctx_t *ctx,
const uint8_t *data,
size_t length);
cl_error_t cl_finish_hash_ex(
cl_hash_ctx_t *ctx,
uint8_t **hash,
size_t *hash_len,
uint32_t flags);
void cl_hash_destroy(void *ctx);
cl_error_t cl_hash_file_fd_ex(
const char *alg,
int fd,
size_t offset,
size_t length,
uint8_t **hash,
size_t *hash_len,
uint32_t flags);
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
*
ClamScan: Improved the precision of the bytes-scanned and bytes-read counte=
rs. The ClamScan scan summary will now report exact counts in "GiB", "MiB",=
"KiB", or "B" as appropriate. Previously, it always reported "MB".
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
*
ClamScan: Add hash & file-type in/out CLI options:
We will not be adding this for ClamDScan, as we do not have a mechanism in =
the ClamD socket API to receive scan options or a way for ClamD to include =
scan metadata in the response.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
* --hash-hint: The file hash so that libclamav does not need to calc=
ulate it. The type of hash must match the --hash-alg.
* --log-hash: Print the file hash after each file scanned. The type =
of hash printed will match the --hash-alg.
* --hash-alg: The hashing algorithm used for either --hash-hint or -=
-log-hash. Supported algorithms are "md5", "sha1", "sha2-256". If not speci=
fied, the default is "sha2-256".
* --file-type-hint: The file type hint so that libclamav can optimiz=
e scanning (e.g., "pe", "elf", "zip", etc.). You may also use ClamAV type n=
ames such as "CL_TYPE_PE". ClamAV will ignore the hint if it is not familia=
r with the specified type. See also: https://docs.clamav.net/appendix/FileT=
ypes.html#file-types
* --log-file-type: Print the file type after each file scanned.
*
libclamav: Added new scan functions that provide additional functionality:
cl_error_t cl_scanfile_ex(
const char *filename,
cl_verdict_t *verdict_out,
const char **last_alert_out,
uint64_t *scanned_out,
const struct cl_engine *engine,
struct cl_scan_options *scanoptions,
void *context,
const char *hash_hint,
char **hash_out,
const char *hash_alg,
const char *file_type_hint,
char **file_type_out);
cl_error_t cl_scandesc_ex(
int desc,
const char *filename,
cl_verdict_t *verdict_out,
const char **last_alert_out,
uint64_t *scanned_out,
const struct cl_engine *engine,
struct cl_scan_options *scanoptions,
void *context,
const char *hash_hint,
char **hash_out,
const char *hash_alg,
const char *file_type_hint,
char **file_type_out);
cl_error_t cl_scanmap_ex(
cl_fmap_t *map,
const char *filename,
cl_verdict_t *verdict_out,
const char **last_alert_out,
uint64_t *scanned_out,
const struct cl_engine *engine,
struct cl_scan_options *scanoptions,
void *context,
const char *hash_hint,
char **hash_out,
const char *hash_alg,
const char *file_type_hint,
char **file_type_out);
The older cl_scan*() functions are now deprecated and may be removed in a f=
uture release. See clamav.h for more details.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
*
libclamav: Added a new engine option to toggle temp directory recursion.
Temp directory recursion is the idea that each object scanned in ClamAV's r=
ecursive extract/scan process will get a new temp subdirectory, mimicking t=
he nesting structure of the file.
Temp directory recursion was introduced in ClamAV 0.103 and is enabled when=
ever --leave-temps / LeaveTemporaryFiles is enabled.
In ClamAV 1.5, an application linking to libclamav can separately enable te=
mp directory recursion if they wish. For ClamScan and ClamD, it will remain=
tied to --leave-temps / LeaveTemporaryFiles options.
The new temp directory recursion option can be enabled with:
cl_engine_set_num(engine, CL_ENGINE_TMPDIR_RECURSION, 1);
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
*
libclamav: Added a class of scan callback functions that can be added with =
the following API function:
void cl_engine_set_scan_callback(struct cl_engine *engine, clcb_scan callba=
ck, cl_scan_callback_t location);
The scan callback location may be configured using the following five value=
s:
Each callback may alter scan behavior using the following return codes:
Each callback is given a pointer to the current scan layer from which they =
can get previous layers, can get the layer's fmap, and then various attribu=
tes of the layer and of the fmap. To make this possible, there are new APIs=
to query scan-layer details and fmap details:
cl_error_t cl_fmap_set_name(cl_fmap_t *map, const char *name);
cl_error_t cl_fmap_get_name(cl_fmap_t *map, const char **name_out);
cl_error_t cl_fmap_set_path(cl_fmap_t *map, const char *path);
cl_error_t cl_fmap_get_path(cl_fmap_t *map, const char **path_out, size_t=
*offset_out, size_t *len_out);
cl_error_t cl_fmap_get_fd(const cl_fmap_t *map, int *fd_out, size_t *offs=
et_out, size_t *len_out);
cl_error_t cl_fmap_get_size(const cl_fmap_t *map, size_t *size_out);
cl_error_t cl_fmap_set_hash(const cl_fmap_t *map, const char *hash_alg, c=
har hash);
cl_error_t cl_fmap_have_hash(const cl_fmap_t *map, const char *hash_alg, =
bool *have_hash_out);
cl_error_t cl_fmap_will_need_hash_later(const cl_fmap_t *map, const char =
*hash_alg);
cl_error_t cl_fmap_get_hash(const cl_fmap_t *map, const char *hash_alg, c=
har **hash_out);
cl_error_t cl_fmap_get_data(const cl_fmap_t *map, size_t offset, size_t l=
en, const uint8_t **data_out, size_t *data_len_out);
cl_error_t cl_scan_layer_get_fmap(cl_scan_layer_t *layer, cl_fmap_t **fma=
p_out);
cl_error_t cl_scan_layer_get_parent_layer(cl_scan_layer_t *layer, cl_scan=
_layer_t **parent_layer_out);
cl_error_t cl_scan_layer_get_type(cl_scan_layer_t *layer, const char **ty=
pe_out);
cl_error_t cl_scan_layer_get_recursion_level(cl_scan_layer_t *layer, uint=
32_t *recursion_level_out);
cl_error_t cl_scan_layer_get_object_id(cl_scan_layer_t *layer, uint64_t *=
object_id_out);
cl_error_t cl_scan_layer_get_last_alert(cl_scan_layer_t *layer, const cha=
r **alert_name_out);
cl_error_t cl_scan_layer_get_attributes(cl_scan_layer_t *layer, uint32_t =
*attributes_out);
This deprecates, but does not immediately remove, the existing scan callbac=
ks:
void cl_engine_set_clcb_pre_cache(struct cl_engine *engine, clcb_pre_cach=
e callback);
void cl_engine_set_clcb_file_inspection(struct cl_engine *engine, clcb_fi=
le_inspection callback);
void cl_engine_set_clcb_pre_scan(struct cl_engine *engine, clcb_pre_scan =
callback);
void cl_engine_set_clcb_post_scan(struct cl_engine *engine, clcb_post_sca=
n callback);
void cl_engine_set_clcb_virus_found(struct cl_engine *engine, clcb_virus_=
found callback);
void cl_engine_set_clcb_hash(struct cl_engine *engine, clcb_hash callback=
);
There is an interactive test program to demonstrate the new callbacks. See:=
examples/ex_scan_callbacks.c
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
* CL_SCAN_CALLBACK_PRE_HASH: Occurs just after basic file-type detec=
tion and before any hashes have been calculated either for the cache or the=
gen-json metadata.
* CL_SCAN_CALLBACK_PRE_SCAN: Occurs before parser modules run and be=
fore pattern matching.
* CL_SCAN_CALLBACK_POST_SCAN: Occurs after pattern matching and afte=
r running parser modules. A.k.a. the scan is complete for this layer.
* CL_SCAN_CALLBACK_ALERT: Occurs each time an alert (detection) woul=
d be triggered during a scan.
* CL_SCAN_CALLBACK_FILE_TYPE: Occurs each time the file type determi=
nation is refined. This may happen more than once per layer.
*
CL_BREAK: Scan aborted by callback. The rest of the scan is skipped. This d=
oes not mark the file as clean or infected, it just skips the rest of the s=
can.
*
CL_SUCCESS / CL_CLEAN: File scan will continue.
For CL_SCAN_CALLBACK_ALERT: This means you want to ignore this specific ale=
rt and keep scanning.
This is different than CL_VERIFIED because it does not affect prior or futu=
re alerts. Return CL_VERIFIED instead if you want to remove prior alerts fo=
r this layer and skip the rest of the scan for this layer.
*
CL_VIRUS: This means you do not trust the file. A new alert will be added.
For CL_SCAN_CALLBACK_ALERT: This means you agree with the alert and no extr=
a alert is needed.
*
CL_VERIFIED: Layer explicitly trusted by the callback and previous alerts r=
emoved for THIS layer. You might want to do this if you trust the hash or v=
erified a digital signature. The rest of the scan will be skipped for THIS =
layer. For contained files, this does NOT mean that the parent or adjacent =
layers are trusted.
*
Signature names that start with "Weak." will no longer alert. Instead, they=
will be tracked internally and can be found in scan metadata JSON. This is=
a step towards enabling alerting signatures to depend on prior Weak indica=
tor matches in the current layer or in child layers.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
*
For the "Generate Metadata JSON" feature:
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
*
The "Viruses" array of alert names has been replaced by two new arrays that=
include additional details beyond just signature name:
* "Indicators" records three types of indicators:
* Strong indicators are for traditional alerting signature mat=
ches and will halt the scan, except in all-match mode.
* Potentially Unwanted indicators will only cause an alert at =
the end of the scan unless a Strong indicator is found. They are treated th=
e same as Strong indicators in all-match mode.
* Weak indicators do not alert and will be leveraged in a futu=
re version as a condition for logical signature matches.
* "Alerts" records only alerting indicators. Events that trust a =
file, such as false positive signatures, will remove affected indicators, a=
nd mark them as "Ignored" in the "Indicators" array.
*
Add new option to calculate and record additional hash types when the "gene=
rate metadata JSON" feature is enabled:
* libclamav option: CL_SCAN_GENERAL_STORE_EXTRA_HASHES
* ClamScan option: --json-store-extra-hashes (default off)
* clamd.conf option: JsonStoreExtraHashes (default 'no')
*
The file hash is now stored as "sha2-256" instead of "FileMD5". If you enab=
le the "extra hashes" option, then it will also record "md5" and "sha1".
*
Each object scanned now has a unique "Object ID".
*
Sigtool: Renamed the sigtool option --sha256 to --sha2-256. The original op=
tion is still functional but is deprecated.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
Other improvements
*
Set a limit on the max-recursion config option. Users will no longer be abl=
e to set max-recursion higher than 100. This change prevents errors on star=
t up or crashes if encountering a file with that many layers of recursion.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1264>
*
Build system: CMake improvements to support compiling for the AIX platform.=
This change is courtesy of GitHub user KamathForAIX.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1387>
*
Improve support for extracting malformed zip archives. This change is court=
esy of Frederick Sell.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1460>
*
Windows: Code quality improvement for the ClamScan and ClamDScan --move and=
--remove options. This change is courtesy of Maxim Suhanov.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1470>
*
Added file type recognition for an initial set of AI model file types.
The file type is accessible to applications using libclamav via the scan ca=
llback functions and as an optional output parameter to the scan functions:=
cl_scanfile_ex(), cl_scanmap_ex(), and cl_scandesc_ex().
When scanning these files, type will now show "CL_TYPE_AI_MODEL" instead of=
"CL_TYPE_BINARY_DATA".
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1476>
*
Added support for inline comments in ClamAV configuration files. This chang=
e is courtesy of GitHub user userwiths.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1308>
*
Disabled the MyDoom hardcoded/heuristic detection because of false positive=
s.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1495>
*
Sigtool: Added support for creating .cdiff and .script patch files for CVDs=
that have underscores in the CVD name. Also improved support for relative =
paths with the --diff command.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1541>
*
Windows: Improved support for file names with UTF-8 characters not found in=
the ANSI or OEM code pages when printing scan results or showing activity =
in the ClamDTOP monitoring utility. Fixed a bug with opening files with suc=
h names with the Sigtool utility.
GitHub pull request #1<https://github.com/Cisco-Talos/clamav/pull/1461>
GitHub pull request #2<https://github.com/Cisco-Talos/clamav/pull/1537>
*
Improved the code quality of the ZIP module. Added inline documentation.
GitHub pull request #1<https://github.com/Cisco-Talos/clamav/pull/1548>
GitHub pull request #2<https://github.com/Cisco-Talos/clamav/pull/1552>
*
Always run scan callbacks for embedded files. Embedded files are found with=
in other files through signature matches instead of by parsing. They will n=
ow be processed the same way and then they can trigger application callback=
s (e.g., "pre-scan", "post-scan", etc.).
This change will impact scans with both the "leave-temps" feature and the "=
force-to-disk" feature enabled, resulting in additional temporary files.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
*
Added DevContainer templates to the ClamAV Git repository in order to make =
it easier to set up AlmaLinux or Debian development environments.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1462>
Bug fixes
*
Reduced email multipart message parser complexity.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1347>
*
Fixed possible undefined behavior in inflate64 module. The inflate64 module=
is a modified version of the zlib library, taken from version 1.2.3 with s=
ome customization and with some cherry-picked fixes. This adds one addition=
al fix from zlib 1.2.9. Thank you to TITAN Team for reporting this issue.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1469>
*
Fixed a bug in ClamD that broke reporting of memory usage on Linux. The STA=
TS command can be used to monitor ClamD directly or through ClamDTOP. The m=
emory stats feature does not work on all platforms (e.g., Windows).
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1465>
*
Windows: Fixed a build issue when the same library dependency is found in t=
wo different locations.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1453>
*
Fixed an infinite loop when scanning some email files in debug-mode. This f=
ix is courtesy of Yoann Lecuyer.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1445>
*
Fixed a stack buffer overflow bug in the phishing signature load process. T=
his fix is courtesy of GitHub user Shivam7-1.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1486>
*
Fixed a race condition in the Freshclam feature tests. This fix is courtesy=
of GitHub user rma-x.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1513>
*
Windows: Fixed a 5-byte heap buffer overread in the Windows unit tests. Thi=
s fix is courtesy of GitHub user Sophie0x2E.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1542>
*
Fix double-extraction of OOXML-based office documents.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
*
ClamBC: Fixed crashes on startup.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
Acknowledgments
Special thanks to the following people for code contributions and bug repor=
ts:
* b1tg
* ChaoticByte
* Frederick Sell
* KamathForAIX
* Mark Carey at SAP
* Maxim Suhanov
* rma-x
* Shivam7-1
* Sophie0x2E
* TITAN Team
* userwiths
* Yoann Lecuyer
Respectfully,
Val
Valerie Snyder (she/they)
ClamAV Development
Talos
Cisco Systems, Inc.
--_000_CH3PR11MB8750A6128542C2A00A343393C633ACH3PR11MB8750namp_
Content-Type: text/html; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable
<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1=
252">
<style type=3D"text/css" style=3D"display:none;"> P {margin-top:0;margin-bo=
ttom:0;} </style>
</head>
<body dir=3D"ltr">
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 10pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
Read this online at <a id=3D"LPlnk571614" href=3D"https://blog.clamav.net/2=
025/08/clamav-150-release-candidate-now.html">
https://blog.clamav.net/2025/08/clamav-150-release-candidate-now.html</a></=
div>
<span style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService,=
Calibri, Helvetica, sans-serif; font-size: 10pt; color: rgb(0, 0, 0);"><br=
>
</span>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
<br>
</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin: 1=
6px 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calib=
ri, Helvetica, sans-serif; font-size: 12pt;" class=3D"elementToProof">
<span style=3D"color: rgb(0, 0, 0);">The ClamAV 1.5.0 release candidat=
e is now available. You may find the source code and installers f=
or this release at
</span><span style=3D"color: rgb(70, 120, 134);"><a style=3D"color: rgb(70,=
120, 134); margin: 0px;" rel=3D"noreferrer noopener" class=3D"Hyperlink SC=
XW232052544 BCX0 OWAAutoLink" id=3D"OWAb71fa3e4-adfb-c3e3-3409-182b28fc8a35=
" target=3D"_blank" href=3D"https://www.clamav.net/downloads">clamav.net/do=
wnloads</a></span><span style=3D"color: rgb(0, 0, 0);"> or on&nbs=
p;the
</span><span style=3D"color: rgb(70, 120, 134);"><a style=3D"color: rgb(70,=
120, 134); margin: 0px;" rel=3D"noreferrer noopener" class=3D"Hyperlink SC=
XW232052544 BCX0 OWAAutoLink" id=3D"OWAd8fbc5b3-29c9-8682-cc8d-8dbc8fc72bbb=
" target=3D"_blank" href=3D"https://github.com/Cisco-Talos/clamav/releases/=
tag/clamav-1.5.0-rc">ClamAV
GitHub release page</a></span><span style=3D"color: rgb(0, 0, 0);">. =
</span></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin: 0=
px 0px 11.2px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService,=
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" cla=
ss=3D"elementToProof">
The release candidate phase is expected to last two to four weeks before we=
publish the stable release. This will depend on whether any changes are re=
quired to stabilize this version. Please take this time to evaluate Cl=
amAV 1.5.0. </div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin: 1=
6px 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calib=
ri, Helvetica, sans-serif; font-size: 12pt;" class=3D"elementToProof">
<span style=3D"color: rgb(0, 0, 0);">Please help us validate this rele=
ase by providing feedback via
</span><span style=3D"color: rgb(70, 120, 134);"><a style=3D"color: rgb(70,=
120, 134); margin: 0px;" rel=3D"noreferrer noopener" class=3D"Hyperlink SC=
XW232052544 BCX0 OWAAutoLink" id=3D"OWA523dc3a5-1611-cf0b-05cc-6681f976ba75=
" target=3D"_blank" href=3D"https://github.com/Cisco-Talos/clamav/issues">G=
itHub
issues</a></span><span style=3D"color: rgb(0, 0, 0);">, via the </span><sp=
an style=3D"color: rgb(70, 120, 134);"><a style=3D"color: rgb(70, 120, 134)=
; margin: 0px;" rel=3D"noreferrer noopener" class=3D"Hyperlink SCXW23205254=
4 BCX0 OWAAutoLink" id=3D"OWA9a2770b5-abfc-af69-1dd6-a8c5120fe0bb" target=
=3D"_blank" href=3D"https://lists.clamav.net/mailman/listinfo/clamav-users"=
>ClamAV
mailing list</a></span><span style=3D"color: rgb(0, 0, 0);"> or on </=
span><span style=3D"color: rgb(70, 120, 134);"><a style=3D"color: rgb(70, 1=
20, 134); margin: 0px;" rel=3D"noreferrer noopener" class=3D"Hyperlink SCXW=
232052544 BCX0 OWAAutoLink" id=3D"OWAeb43d119-2e71-25ac-3e44-e469ed634541" =
target=3D"_blank" href=3D"https://discord.gg/sGaxA5Q">our
Discord</a></span><span style=3D"color: rgb(0, 0, 0);">. </span></div=
>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin: 1=
6px 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calib=
ri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class=3D"=
elementToProof">
<i>IMPORTANT: A major feature of the 1.5 release is a FIPS-compli=
ant method for verifying the authenticity of CVD signature database archive=
s and CDIFF signature database patch files. The feature is ready to test in=
this release candidate, but we are not yet
distributing the associated =93.cvd.sign=94 signature files for the daily,=
main, and bytecode databases. Because these files are not available, =
ClamAV will fall back to using the legacy MD5-based RSA signature chec=
k. In other words, Freshclam will continue to
fail on FIPS-enabled systems for now. However, the unit tests do incl=
ude a test signing key and certificate pair along with tests to exercise si=
gning and verification using the FIPS-compliant method.</i> </div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin: 1=
6px 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calib=
ri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class=3D"=
elementToProof">
<i>Note: Windows builds on GitHub Actions, which use VCPkg to pro=
vide C library dependencies, are failing at this time.</i> </div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin: 1=
6px 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calib=
ri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class=3D"=
elementToProof">
<i>Tip: If you are downloading the source from the GitHub release page, the=
package labeled "clamav-1.5.0-release candidate.tar.gz" does not=
require an internet connection to build. All dependencies are included in =
this package. However, if you download the
ZIP or TAR.GZ generated by GitHub, located at the very bottom, then a=
n internet connection will be required during the build to download ad=
ditional Rust dependencies.</i> </div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin: 0=
px 0px 11.2px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService,=
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" cla=
ss=3D"elementToProof">
For Docker users, there is no specific Docker tag for the release candidate=
, but you can use the clamav:unstable or clamav:unstable_base tag=
s. </div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin: 0=
px 0px 16px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class=
=3D"elementToProof">
ClamAV 1.5.0 includes the following improvements and changes: </div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin: 24px 0px 16px; font-family: Aptos, Aptos_EmbeddedFont, Ap=
tos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: =
rgb(0, 0, 0);" class=3D"elementToProof" id=3D"major-changes">
<b>Major changes</b></div>
<ul style=3D"direction: ltr; text-align: left; margin: 0px 0px 0.7em; paddi=
ng-right: 2.5em; padding-left: 2.5em; list-style-position: initial; list-st=
yle-type: disc;" data-line=3D"11">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Added checks to determine if an OLE2-based Microsoft Office document is enc=
rypted.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1295" class=3D"OWAAutoLink" id=3D"OWA05a2a9cd-c9b0-9b00-c=
e23-eda240c71387" href=3D"https://github.com/Cisco-Talos/clamav/pull/1295">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Added the ability to record URIs found in HTML if the generate-JSON-metadat=
a feature is enabled. Also adds an option to disable this in case you want =
the JSON metadata feature but do not want to record HTML URIs. The ClamScan=
command-line option is
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
--json-store-html-uris=3Dno</code></span>. The
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
clamd.conf</code></span> config option is
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
JsonStoreHTMLURIs no</code></span>. The libclamav general scan option is
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
CL_SCAN_GENERAL_STORE_HTML_URIS</code></span></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1281" class=3D"OWAAutoLink" id=3D"OWA78c1ee0d-0a95-c703-6=
3b5-dd0eb08b4253" href=3D"https://github.com/Cisco-Talos/clamav/pull/1281">=
GitHub pull request #1</a></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1482" class=3D"OWAAutoLink" id=3D"OWA69d994c6-b06f-a0f5-6=
fda-f5113bba38c0" href=3D"https://github.com/Cisco-Talos/clamav/pull/1482">=
GitHub pull request #2</a></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1514" class=3D"OWAAutoLink" id=3D"OWAf43b3b6c-3c47-1396-a=
f13-b3104ee1ae8f" href=3D"https://github.com/Cisco-Talos/clamav/pull/1514">=
GitHub pull request #3</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Added the ability to record URIs found in PDFs if the generate-JSON-metadat=
a feature is enabled. Also adds an option to disable this in case you want =
the JSON metadata feature but do not want to record PDF URIs. The ClamScan =
command-line option is
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
--json-store-pdf-uris=3Dno</code></span>. The
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
clamd.conf</code></span> config option is
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
JsonStorePDFURIs no</code></span>. The libclamav general scan option is
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
CL_SCAN_GENERAL_STORE_PDF_URIS</code></span></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1482" class=3D"OWAAutoLink" id=3D"OWA852d7d5a-f07b-3c88-b=
571-9d6752a8c195" href=3D"https://github.com/Cisco-Talos/clamav/pull/1482">=
GitHub pull request #1</a></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1514" class=3D"OWAAutoLink" id=3D"OWA4fead452-3c7f-8773-3=
5cc-9160137c87be" href=3D"https://github.com/Cisco-Talos/clamav/pull/1514">=
GitHub pull request #2</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Added regex support for the <span style=3D"font-family: Consolas, "Cou=
rier New", monospace;">
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
clamd.conf</code></span> <span style=3D"font-family: Consolas, "C=
ourier New", monospace;"><code style=3D"font-family: Consolas, "C=
ourier New", monospace;">OnAccessExcludePath</code></span> config=
option.
This change courtesy of GitHub user b1tg.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1314" class=3D"OWAAutoLink" id=3D"OWAbf99d4d2-4dfa-164d-d=
931-c3238e9f92ed" href=3D"https://github.com/Cisco-Talos/clamav/pull/1314">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Added CVD signing/verification with external <span style=3D"font-family: Co=
nsolas, "Courier New", monospace;">
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
.sign</code></span> files.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Freshclam will now attempt to download external signature files to accompan=
y existing
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
.cvd</code></span> databases and
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
.cdiff</code></span> patch files. Sigtool now has commands to sign and=
verify using the external signatures.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
ClamAV now installs a 'certs' directory in the app config directory (e.g., =
<span style=3D"font-family: Consolas, "Courier New", monospace;">
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
<prefix>/etc/certs</code></span>). The install path is configurable. =
The CMake option to configure the CVD certs directory is
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
-D CVD_CERTS_DIRECTORY=3DPATH</code></span></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
New options to set an alternative CVD certs directory:</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Added two new APIs to the public clamav.h header:</div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 0.8px; border-s=
tyle: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D=
"presentation" class=3D"elementToProof"><div style=3D"font-family: Consolas=
, "Courier New", monospace;" class=3D"elementToProof"><span style=
=3D"line-height: 1.357em;"><code style=3D"font-family: Consolas, "Cour=
ier New", monospace; display: inline-block;">cl_error_t cl_cvdverify_e=
x(=0A=
const char *file,=0A=
const char *certs_directory,=0A=
uint32_t dboptions);=0A=
=0A=
cl_error_t cl_cvdunpack_ex(=0A=
const char *file,=0A=
const char *dir,=0A=
const char *certs_directory,=0A=
uint32_t dboptions);=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
The original <span style=3D"font-family: Consolas, "Courier New",=
monospace;"><code style=3D"font-family: Consolas, "Courier New",=
monospace;">cl_cvdverify</code></span> and
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
cl_cvdunpack</code></span> are deprecated.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Added a <span style=3D"font-family: Consolas, "Courier New", mono=
space;"><code style=3D"font-family: Consolas, "Courier New", mono=
space;">cl_engine_field</code></span> enum option
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
CL_ENGINE_CVDCERTSDIR</code></span>. You may set this option with
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
cl_engine_set_str</code></span> and get it with
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
cl_engine_get_str</code></span>, to override the compiled in default CVD ce=
rts directory.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Thank you to Mark Carey at SAP for inspiring work on this feature with an i=
nitial proof of concept for external-signature FIPS compliant CVD signing.<=
/div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1417" class=3D"OWAAutoLink" id=3D"OWAb5184d4e-2ca5-6bb9-a=
905-c5882333e245" href=3D"https://github.com/Cisco-Talos/clamav/pull/1417">=
GitHub pull request #1</a></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1478" class=3D"OWAAutoLink" id=3D"OWAdc848458-6848-14d8-5=
365-666eac927bef" href=3D"https://github.com/Cisco-Talos/clamav/pull/1478">=
GitHub pull request #2</a></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1489" class=3D"OWAAutoLink" id=3D"OWA4529ee9b-7a60-dbc1-2=
263-da9794b4b35b" href=3D"https://github.com/Cisco-Talos/clamav/pull/1489">=
GitHub pull request #3</a></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1491" class=3D"OWAAutoLink" id=3D"OWAe6d8ec8b-15a7-db44-b=
42c-1590acd95882" href=3D"https://github.com/Cisco-Talos/clamav/pull/1491">=
GitHub pull request #4</a></div>
</li><ul style=3D"direction: ltr; text-align: left; margin: 0px 0px 0.7em; =
padding-right: 2.5em; padding-left: 2.5em; list-style-position: initial; li=
st-style-type: disc; flex-direction: column; display: flex;" data-line=3D"5=
9">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; align-self: start; text-indent: 0px; margin: 0px 0px 0.25em;">
The command-line option for Freshclam, ClamD, ClamScan, and Sigtool is <spa=
n role=3D"presentation" style=3D"font-family: Consolas, "Courier New&q=
uot;, monospace;">
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
--cvdcertsdir PATH</code></span></li><li style=3D"font-family: Aptos, Aptos=
_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-si=
ze: 12pt; color: rgb(0, 0, 0); direction: ltr; align-self: start; text-inde=
nt: 0px; margin: 0px 0px 0.25em;">
The environment variable for Freshclam, ClamD, ClamScan, and Sigtool is <sp=
an role=3D"presentation" style=3D"font-family: Consolas, "Courier New&=
quot;, monospace;">
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
CVD_CERTS_DIR</code></span></li><li style=3D"font-family: Aptos, Aptos_Embe=
ddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 1=
2pt; color: rgb(0, 0, 0); direction: ltr; align-self: start; text-indent: 0=
px; margin: 0px 0px 0.25em;">
The config option for Freshclam and ClamD is <span role=3D"presentation" st=
yle=3D"font-family: Consolas, "Courier New", monospace;">
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
CVDCertsDirectory PATH</code></span></li></ul>
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Freshclam, ClamD, ClamScan, and Sigtool: Added an option to enable FIPS-lik=
e limits disabling MD5 and SHA1 from being used for verifying digital signa=
tures or for being used to trust a file when checking for false positives (=
FPs).</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
For <span style=3D"font-family: Consolas, "Courier New", monospac=
e;"><code style=3D"font-family: Consolas, "Courier New", monospac=
e;">freshclam.conf</code></span> and
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
clamd.conf</code></span> set this config option:</div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 0.8px; border-s=
tyle: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D=
"presentation" class=3D"elementToProof"><div style=3D"font-family: Consolas=
, "Courier New", monospace;" class=3D"elementToProof"><span style=
=3D"line-height: 1.357em;"><code style=3D"font-family: Consolas, "Cour=
ier New", monospace; display: inline-block;">FIPSCryptoHashLimits yes=
=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
For <span style=3D"font-family: Consolas, "Courier New", monospac=
e;"><code style=3D"font-family: Consolas, "Courier New", monospac=
e;">clamscan</code></span> and
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
sigtool</code></span> use this command-line option:</div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 0.8px; border-s=
tyle: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D=
"presentation" class=3D"elementToProof"><div style=3D"font-family: Consolas=
, "Courier New", monospace;" class=3D"elementToProof"><span style=
=3D"line-height: 1.357em;"><code style=3D"font-family: Consolas, "Cour=
ier New", monospace; display: inline-block;">--fips-limits=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
For libclamav: Enable FIPS-limits for a ClamAV engine like this:</div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 0.8px; border-s=
tyle: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D=
"presentation" class=3D"elementToProof"><div style=3D"font-family: Consolas=
, "Courier New", monospace;" class=3D"elementToProof"><span style=
=3D"line-height: 1.357em;"><code style=3D"font-family: Consolas, "Cour=
ier New", monospace; display: inline-block;">cl_engine_set_num(engine,=
CL_ENGINE_FIPS_LIMITS, 1);=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
ClamAV will also attempt to detect if FIPS-mode is enabled. If so, it will =
automatically enable the FIPS-limits feature.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
This change mitigates safety concerns over the use of MD5 and SHA1 algorith=
ms to trust files and is required to enable ClamAV to operate legitimately =
in FIPS-mode enabled environments.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Note: ClamAV may still calculate MD5 or SHA1 hashes as needed for detection=
purposes or for informational purposes in FIPS-enabled environments and wh=
en the FIPS-limits option is enabled.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWA3bc6c935-6fa4-22ae-8=
456-022cacd80bca" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Upgraded the clean-file scan cache to use SHA2-256 (prior versions use MD5)=
. The clean-file cache algorithm is not configurable.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
This change resolves safety concerns over the use of MD5 to trust files and=
is required to enable ClamAV to operate legitimately in FIPS-mode enabled =
environments.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWA9d847376-e446-36d0-5=
909-d1f8176d7ad7" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
ClamD: Added an option to disable select administrative commands including =
<span style=3D"font-family: Consolas, "Courier New", monospace;">
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
SHUTDOWN</code></span>,
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
RELOAD</code></span>,
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
STATS</code></span> and
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
VERSION</code></span>.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
The new <span style=3D"font-family: Consolas, "Courier New", mono=
space;"><code style=3D"font-family: Consolas, "Courier New", mono=
space;">clamd.conf</code></span> options are:</div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 0.8px; border-s=
tyle: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D=
"presentation" class=3D"elementToProof"><div style=3D"font-family: Consolas=
, "Courier New", monospace;" class=3D"elementToProof"><span style=
=3D"line-height: 1.357em;"><code style=3D"font-family: Consolas, "Cour=
ier New", monospace; display: inline-block;">EnableShutdownCommand yes=
=0A=
EnableReloadCommand yes=0A=
EnableStatsCommand yes=0A=
EnableVersionCommand yes=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
This change courtesy of GitHub user ChaoticByte.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1502" class=3D"OWAAutoLink" id=3D"OWA05231360-4ef1-b33b-0=
51e-8dba35d99d3e" href=3D"https://github.com/Cisco-Talos/clamav/pull/1502">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
libclamav: Added extended hashing functions with a "flags" parame=
ter that allows the caller to choose if they want to bypass FIPS hash algor=
ithm limits:</div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 0.8px; border-s=
tyle: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D=
"presentation" class=3D"elementToProof"><div style=3D"font-family: Consolas=
, "Courier New", monospace;" class=3D"elementToProof"><span style=
=3D"line-height: 1.357em;"><code style=3D"font-family: Consolas, "Cour=
ier New", monospace; display: inline-block;">cl_error_t cl_hash_data_e=
x(=0A=
const char *alg,=0A=
const uint8_t *data,=0A=
size_t data_len,=0A=
uint8_t **hash,=0A=
size_t *hash_len,=0A=
uint32_t flags);=0A=
=0A=
cl_error_t cl_hash_init_ex(=0A=
const char *alg,=0A=
uint32_t flags,=0A=
cl_hash_ctx_t **ctx_out);=0A=
=0A=
cl_error_t cl_update_hash_ex(=0A=
cl_hash_ctx_t *ctx,=0A=
const uint8_t *data,=0A=
size_t length);=0A=
=0A=
cl_error_t cl_finish_hash_ex(=0A=
cl_hash_ctx_t *ctx,=0A=
uint8_t **hash,=0A=
size_t *hash_len,=0A=
uint32_t flags);=0A=
=0A=
void cl_hash_destroy(void *ctx);=0A=
=0A=
cl_error_t cl_hash_file_fd_ex(=0A=
const char *alg,=0A=
int fd,=0A=
size_t offset,=0A=
size_t length,=0A=
uint8_t **hash,=0A=
size_t *hash_len,=0A=
uint32_t flags);=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWA73d13217-d993-7e10-6=
4e9-8a24739754d7" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
ClamScan: Improved the precision of the bytes-scanned and bytes-read counte=
rs. The ClamScan scan summary will now report exact counts in "GiB&quo=
t;, "MiB", "KiB", or "B" as appropriate. Prev=
iously, it always reported "MB".</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWA331054d8-2133-dac4-2=
005-fcbf0d2b7110" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
ClamScan: Add hash & file-type in/out CLI options:</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
We will not be adding this for ClamDScan, as we do not have a mechanism in =
the ClamD socket API to receive scan options or a way for ClamD to include =
scan metadata in the response.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWA6a2e29da-f569-be47-3=
b75-4f096fcbff0a" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><ul style=3D"direction: ltr; text-align: left; margin: 0px 0px 0.7em; =
padding-right: 2.5em; padding-left: 2.5em; list-style-position: initial; li=
st-style-type: disc; flex-direction: column; display: flex;" data-line=3D"1=
99">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; align-self: start; text-indent: 0px; margin: 0px 0px 0.25em;">
<span role=3D"presentation" style=3D"font-family: Consolas, "Courier N=
ew", monospace;"><code style=3D"font-family: Consolas, "Courier N=
ew", monospace;">--hash-hint</code></span>: The file hash so that libc=
lamav does not need to calculate it. The type of hash must
match the <span role=3D"presentation" style=3D"font-family: Consolas, &quo=
t;Courier New", monospace;">
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
--hash-alg</code></span>.</li><li style=3D"font-family: Aptos, Aptos_Embedd=
edFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12p=
t; color: rgb(0, 0, 0); direction: ltr; align-self: start; text-indent: 0px=
; margin: 0px 0px 0.25em;">
<span role=3D"presentation" style=3D"font-family: Consolas, "Courier N=
ew", monospace;"><code style=3D"font-family: Consolas, "Courier N=
ew", monospace;">--log-hash</code></span>: Print the file hash after e=
ach file scanned. The type of hash printed will match the
<span role=3D"presentation" style=3D"font-family: Consolas, "Courier N=
ew", monospace;">
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
--hash-alg</code></span>.</li><li style=3D"font-family: Aptos, Aptos_Embedd=
edFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12p=
t; color: rgb(0, 0, 0); direction: ltr; align-self: start; text-indent: 0px=
; margin: 0px 0px 0.25em;">
<span role=3D"presentation" style=3D"font-family: Consolas, "Courier N=
ew", monospace;"><code style=3D"font-family: Consolas, "Courier N=
ew", monospace;">--hash-alg</code></span>: The hashing algorithm used =
for either
<span role=3D"presentation" style=3D"font-family: Consolas, "Courier N=
ew", monospace;">
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
--hash-hint</code></span> or
<span role=3D"presentation" style=3D"font-family: Consolas, "Courier N=
ew", monospace;">
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
--log-hash</code></span>. Supported algorithms are "md5", "s=
ha1", "sha2-256". If not specified, the default is "sha=
2-256".</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos=
_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb=
(0, 0, 0); direction: ltr; align-self: start; text-indent: 0px; margin: 0px=
0px 0.25em;">
<span role=3D"presentation" style=3D"font-family: Consolas, "Courier N=
ew", monospace;"><code style=3D"font-family: Consolas, "Courier N=
ew", monospace;">--file-type-hint</code></span>: The file type hint so=
that libclamav can optimize scanning (e.g., "pe", "elf"=
;,
"zip", etc.). You may also use ClamAV type names such as "C=
L_TYPE_PE". ClamAV will ignore the hint if it is not familiar with the=
specified type. See also:
<span role=3D"presentation" style=3D"color: rgb(0, 95, 184);"><a style=3D"c=
olor: rgb(0, 95, 184);" data-href=3D"https://docs.clamav.net/appendix/FileT=
ypes.html#file-types" class=3D"OWAAutoLink" id=3D"OWA285a709b-a28e-9de4-5ca=
b-f1e4a636f9a9" href=3D"https://docs.clamav.net/appendix/FileTypes.html#fil=
e-types">https://docs.clamav.net/appendix/FileTypes.html#file-types</a></sp=
an></li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontSe=
rvice, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0)=
; direction: ltr; align-self: start; text-indent: 0px; margin: 0px 0px 0.25=
em;">
<span role=3D"presentation" style=3D"font-family: Consolas, "Courier N=
ew", monospace;"><code style=3D"font-family: Consolas, "Courier N=
ew", monospace;">--log-file-type</code></span>: Print the file type af=
ter each file scanned.</li></ul>
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
libclamav: Added new scan functions that provide additional functionality:<=
/div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 0.8px; border-s=
tyle: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D=
"presentation" class=3D"elementToProof"><div style=3D"font-family: Consolas=
, "Courier New", monospace;" class=3D"elementToProof"><span style=
=3D"line-height: 1.357em;"><code style=3D"font-family: Consolas, "Cour=
ier New", monospace; display: inline-block;">cl_error_t cl_scanfile_ex=
(=0A=
const char *filename,=0A=
cl_verdict_t *verdict_out,=0A=
const char **last_alert_out,=0A=
uint64_t *scanned_out,=0A=
const struct cl_engine *engine,=0A=
struct cl_scan_options *scanoptions,=0A=
void *context,=0A=
const char *hash_hint,=0A=
char **hash_out,=0A=
const char *hash_alg,=0A=
const char *file_type_hint,=0A=
char **file_type_out);=0A=
=0A=
cl_error_t cl_scandesc_ex(=0A=
int desc,=0A=
const char *filename,=0A=
cl_verdict_t *verdict_out,=0A=
const char **last_alert_out,=0A=
uint64_t *scanned_out,=0A=
const struct cl_engine *engine,=0A=
struct cl_scan_options *scanoptions,=0A=
void *context,=0A=
const char *hash_hint,=0A=
char **hash_out,=0A=
const char *hash_alg,=0A=
const char *file_type_hint,=0A=
char **file_type_out);=0A=
=0A=
cl_error_t cl_scanmap_ex(=0A=
cl_fmap_t *map,=0A=
const char *filename,=0A=
cl_verdict_t *verdict_out,=0A=
const char **last_alert_out,=0A=
uint64_t *scanned_out,=0A=
const struct cl_engine *engine,=0A=
struct cl_scan_options *scanoptions,=0A=
void *context,=0A=
const char *hash_hint,=0A=
char **hash_out,=0A=
const char *hash_alg,=0A=
const char *file_type_hint,=0A=
char **file_type_out);=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
The older <span style=3D"font-family: Consolas, "Courier New", mo=
nospace;"><code style=3D"font-family: Consolas, "Courier New", mo=
nospace;">cl_scan*()</code></span> functions are now deprecated and ma=
y be removed in a future release. See
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
clamav.h</code></span> for more details.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWAf63446d2-5b60-b26e-f=
e76-9644a15826e6" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
libclamav: Added a new engine option to toggle temp directory recursion.</d=
iv>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Temp directory recursion is the idea that each object scanned in ClamAV's r=
ecursive extract/scan process will get a new temp subdirectory, mimicking t=
he nesting structure of the file.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Temp directory recursion was introduced in ClamAV 0.103 and is enabled when=
ever <span style=3D"font-family: Consolas, "Courier New", monospa=
ce;">
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
--leave-temps</code></span> /
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
LeaveTemporaryFiles</code></span> is enabled.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
In ClamAV 1.5, an application linking to libclamav can separately enable te=
mp directory recursion if they wish. For ClamScan and ClamD, it will remain=
tied to
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
--leave-temps</code></span> /
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
LeaveTemporaryFiles</code></span> options.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
The new temp directory recursion option can be enabled with:</div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 0.8px; border-s=
tyle: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D=
"presentation" class=3D"elementToProof"><div style=3D"font-family: Consolas=
, "Courier New", monospace;" class=3D"elementToProof"><span style=
=3D"line-height: 1.357em;"><code style=3D"font-family: Consolas, "Cour=
ier New", monospace; display: inline-block;">cl_engine_set_num(engine,=
CL_ENGINE_TMPDIR_RECURSION, 1);=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWA6fec7a57-52a8-4777-b=
56e-7e0f02df6e77" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
libclamav: Added a class of scan callback functions that can be added with =
the following API function:</div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 0.8px; border-s=
tyle: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D=
"presentation" class=3D"elementToProof"><div style=3D"font-family: Consolas=
, "Courier New", monospace;" class=3D"elementToProof"><span style=
=3D"line-height: 1.357em;"><code style=3D"font-family: Consolas, "Cour=
ier New", monospace; display: inline-block;">void cl_engine_set_scan_c=
allback(struct cl_engine *engine, clcb_scan callback, cl_scan_callback_t lo=
cation);=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
The scan callback location may be configured using the following five value=
s:</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Each callback may alter scan behavior using the following return codes:</di=
v>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Each callback is given a pointer to the current scan layer from which they =
can get previous layers, can get the layer's fmap, and then various attribu=
tes of the layer and of the fmap. To make this possible, there are new APIs=
to query scan-layer details and
fmap details:</div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 0.8px; border-s=
tyle: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D=
"presentation" class=3D"elementToProof"><div style=3D"font-family: Consolas=
, "Courier New", monospace;" class=3D"elementToProof"><span style=
=3D"line-height: 1.357em;"><code style=3D"font-family: Consolas, "Cour=
ier New", monospace; display: inline-block;"> cl_error_t cl_fmap=
_set_name(cl_fmap_t *map, const char *name);=0A=
cl_error_t cl_fmap_get_name(cl_fmap_t *map, const char **name_out);=
=0A=
cl_error_t cl_fmap_set_path(cl_fmap_t *map, const char *path);=0A=
cl_error_t cl_fmap_get_path(cl_fmap_t *map, const char **path_out, s=
ize_t *offset_out, size_t *len_out);=0A=
cl_error_t cl_fmap_get_fd(const cl_fmap_t *map, int *fd_out, size_t =
*offset_out, size_t *len_out);=0A=
cl_error_t cl_fmap_get_size(const cl_fmap_t *map, size_t *size_out);=
=0A=
cl_error_t cl_fmap_set_hash(const cl_fmap_t *map, const char *hash_a=
lg, char hash);=0A=
cl_error_t cl_fmap_have_hash(const cl_fmap_t *map, const char *hash_=
alg, bool *have_hash_out);=0A=
cl_error_t cl_fmap_will_need_hash_later(const cl_fmap_t *map, const =
char *hash_alg);=0A=
cl_error_t cl_fmap_get_hash(const cl_fmap_t *map, const char *hash_a=
lg, char **hash_out);=0A=
cl_error_t cl_fmap_get_data(const cl_fmap_t *map, size_t offset, siz=
e_t len, const uint8_t **data_out, size_t *data_len_out);=0A=
cl_error_t cl_scan_layer_get_fmap(cl_scan_layer_t *layer, cl_fmap_t =
**fmap_out);=0A=
cl_error_t cl_scan_layer_get_parent_layer(cl_scan_layer_t *layer, cl=
_scan_layer_t **parent_layer_out);=0A=
cl_error_t cl_scan_layer_get_type(cl_scan_layer_t *layer, const char=
**type_out);=0A=
cl_error_t cl_scan_layer_get_recursion_level(cl_scan_layer_t *layer,=
uint32_t *recursion_level_out);=0A=
cl_error_t cl_scan_layer_get_object_id(cl_scan_layer_t *layer, uint6=
4_t *object_id_out);=0A=
cl_error_t cl_scan_layer_get_last_alert(cl_scan_layer_t *layer, cons=
t char **alert_name_out);=0A=
cl_error_t cl_scan_layer_get_attributes(cl_scan_layer_t *layer, uint=
32_t *attributes_out);=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
This deprecates, but does not immediately remove, the existing scan callbac=
ks:</div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 0.8px; border-s=
tyle: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D=
"presentation" class=3D"elementToProof"><div style=3D"font-family: Consolas=
, "Courier New", monospace;" class=3D"elementToProof"><span style=
=3D"line-height: 1.357em;"><code style=3D"font-family: Consolas, "Cour=
ier New", monospace; display: inline-block;"> void cl_engine_set=
_clcb_pre_cache(struct cl_engine *engine, clcb_pre_cache callback);=0A=
void cl_engine_set_clcb_file_inspection(struct cl_engine *engine, cl=
cb_file_inspection callback);=0A=
void cl_engine_set_clcb_pre_scan(struct cl_engine *engine, clcb_pre_=
scan callback);=0A=
void cl_engine_set_clcb_post_scan(struct cl_engine *engine, clcb_pos=
t_scan callback);=0A=
void cl_engine_set_clcb_virus_found(struct cl_engine *engine, clcb_v=
irus_found callback);=0A=
void cl_engine_set_clcb_hash(struct cl_engine *engine, clcb_hash cal=
lback);=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
There is an interactive test program to demonstrate the new callbacks. See:=
<span style=3D"font-family: Consolas, "Courier New", monospace;"=
>
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
examples/ex_scan_callbacks.c</code></span></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWA5a2a637e-d9d9-cff8-c=
1af-5950153c6d44" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><ul style=3D"direction: ltr; text-align: left; margin: 0px 0px 0.7em; =
padding-right: 2.5em; padding-left: 2.5em; list-style-position: initial; li=
st-style-type: disc; flex-direction: column; display: flex;" data-line=3D"2=
99">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; align-self: start; text-indent: 0px; margin: 0px 0px 0.25em;">
<span role=3D"presentation" style=3D"font-family: Consolas, "Courier N=
ew", monospace;"><code style=3D"font-family: Consolas, "Courier N=
ew", monospace;">CL_SCAN_CALLBACK_PRE_HASH</code></span>: Occurs just =
after basic file-type detection and before any hashes have
been calculated either for the cache or the gen-json metadata.</li><li sty=
le=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri,=
Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direction: lt=
r; align-self: start; text-indent: 0px; margin: 0px 0px 0.25em;">
<span role=3D"presentation" style=3D"font-family: Consolas, "Courier N=
ew", monospace;"><code style=3D"font-family: Consolas, "Courier N=
ew", monospace;">CL_SCAN_CALLBACK_PRE_SCAN</code></span>: Occurs befor=
e parser modules run and before pattern matching.</li><li style=3D"font-fam=
ily: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sa=
ns-serif; font-size: 12pt; color: rgb(0, 0, 0); direction: ltr; align-self:=
start; text-indent: 0px; margin: 0px 0px 0.25em;">
<span role=3D"presentation" style=3D"font-family: Consolas, "Courier N=
ew", monospace;"><code style=3D"font-family: Consolas, "Courier N=
ew", monospace;">CL_SCAN_CALLBACK_POST_SCAN</code></span>: Occurs afte=
r pattern matching and after running parser modules. A.k.a.
the scan is complete for this layer.</li><li style=3D"font-family: Aptos, =
Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; fo=
nt-size: 12pt; color: rgb(0, 0, 0); direction: ltr; align-self: start; text=
-indent: 0px; margin: 0px 0px 0.25em;">
<span role=3D"presentation" style=3D"font-family: Consolas, "Courier N=
ew", monospace;"><code style=3D"font-family: Consolas, "Courier N=
ew", monospace;">CL_SCAN_CALLBACK_ALERT</code></span>: Occurs each tim=
e an alert (detection) would be triggered during a scan.</li><li style=3D"f=
ont-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvet=
ica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direction: ltr; alig=
n-self: start; text-indent: 0px; margin: 0px 0px 0.25em;">
<span role=3D"presentation" style=3D"font-family: Consolas, "Courier N=
ew", monospace;"><code style=3D"font-family: Consolas, "Courier N=
ew", monospace;">CL_SCAN_CALLBACK_FILE_TYPE</code></span>: Occurs each=
time the file type determination is refined. This may happen
more than once per layer.</li><li style=3D"font-family: Aptos, Aptos_Embed=
dedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12=
pt; color: rgb(0, 0, 0); direction: ltr; text-indent: 0px; margin: 0px 0px =
0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
CL_BREAK</code></span>: Scan aborted by callback. The rest of the scan is s=
kipped. This does not mark the file as clean or infected,
it just skips the rest of the scan.</div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
CL_SUCCESS</code></span> /
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
CL_CLEAN</code></span>: File scan will continue.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
For <span style=3D"font-family: Consolas, "Courier New", monospac=
e;"><code style=3D"font-family: Consolas, "Courier New", monospac=
e;">CL_SCAN_CALLBACK_ALERT</code></span>: This means you want to ignore thi=
s specific alert and keep scanning.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
This is different than <span style=3D"font-family: Consolas, "Courier =
New", monospace;">
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
CL_VERIFIED</code></span> because it does not affect prior or future a=
lerts. Return
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
CL_VERIFIED</code></span> instead if you want to remove prior alerts f=
or this layer and skip the rest of the scan for this layer.</div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
CL_VIRUS</code></span>: This means you do not trust the file. A new alert w=
ill be added.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
For <span style=3D"font-family: Consolas, "Courier New", monospac=
e;"><code style=3D"font-family: Consolas, "Courier New", monospac=
e;">CL_SCAN_CALLBACK_ALERT</code></span>: This means you agree with the ale=
rt and no extra alert is needed.</div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
CL_VERIFIED</code></span>: Layer explicitly trusted by the callback and pre=
vious alerts removed for THIS layer. You might want to do
this if you trust the hash or verified a digital signature. The rest of th=
e scan will be skipped for THIS layer. For contained files, this does NOT m=
ean that the parent or adjacent layers are trusted.</div>
</li></ul>
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Signature names that start with "Weak." will no longer alert. Ins=
tead, they will be tracked internally and can be found in scan metadata JSO=
N. This is a step towards enabling alerting signatures to depend on prior W=
eak indicator matches in the current layer
or in child layers.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWAa5cb0bb8-f6a6-7583-0=
10e-9434418dc196" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
For the "Generate Metadata JSON" feature:</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWA8315bc02-585f-7762-0=
c4b-6ea8c3a70387" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><ul style=3D"direction: ltr; text-align: left; margin: 0px 0px 0.7em; =
padding-right: 2.5em; padding-left: 2.5em; list-style-position: initial; li=
st-style-type: disc;" data-line=3D"386">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
The "Viruses" array of alert names has been replaced by two new a=
rrays that include additional details beyond just signature name:</div>
</li><ul style=3D"direction: ltr; text-align: left; margin: 0px 0px 0.7em; =
padding-right: 2.5em; padding-left: 2.5em; list-style-position: initial; li=
st-style-type: disc; flex-direction: column; display: flex;" data-line=3D"3=
88">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; align-self: start; text-indent: 0px; margin: 0px 0px 0.25em;">
"Indicators" records three types of indicators:</li><ul style=3D"=
direction: ltr; text-align: left; margin: 0px; padding-right: 2.5em; paddin=
g-left: 2.5em; list-style-position: initial; list-style-type: disc; flex-di=
rection: column; display: flex;" data-line=3D"389">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; align-self: start; text-indent: 0px; margin: 0px 0px 0.25em;">
<b>Strong</b> indicators are for traditional alerting signature matche=
s and will halt the scan, except in all-match mode.</li><li style=3D"font-f=
amily: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, =
sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direction: ltr; align-sel=
f: start; text-indent: 0px; margin: 0px 0px 0.25em;">
<b>Potentially Unwanted</b> indicators will only cause an alert at the=
end of the scan unless a Strong indicator is found. They are treated the s=
ame as Strong indicators in all-match mode.</li><li style=3D"font-family: A=
ptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-ser=
if; font-size: 12pt; color: rgb(0, 0, 0); direction: ltr; align-self: start=
; text-indent: 0px; margin: 0px 0px 0.25em;">
<b>Weak</b> indicators do not alert and will be leveraged in a future =
version as a condition for logical signature matches.</li></ul>
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; align-self: start; text-indent: 0px; margin: 0px 0px 0.25em;">
"Alerts" records only alerting indicators. Events that trust a fi=
le, such as false positive signatures, will remove affected indicators, and=
mark them as "Ignored" in the "Indicators" array.</li>=
</ul>
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Add new option to calculate and record additional hash types when the "=
;generate metadata JSON" feature is enabled:</div>
</li><ul style=3D"direction: ltr; text-align: left; margin: 0px 0px 0.7em; =
padding-right: 2.5em; padding-left: 2.5em; list-style-position: initial; li=
st-style-type: disc; flex-direction: column; display: flex;" data-line=3D"4=
02">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; align-self: start; text-indent: 0px; margin: 0px 0px 0.25em;">
libclamav option: <span role=3D"presentation" style=3D"font-family: Consola=
s, "Courier New", monospace;">
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
CL_SCAN_GENERAL_STORE_EXTRA_HASHES</code></span></li><li style=3D"font-fami=
ly: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, san=
s-serif; font-size: 12pt; color: rgb(0, 0, 0); direction: ltr; align-self: =
start; text-indent: 0px; margin: 0px 0px 0.25em;">
ClamScan option: <span role=3D"presentation" style=3D"font-family: Consolas=
, "Courier New", monospace;">
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
--json-store-extra-hashes</code></span> (default off)</li><li style=3D=
"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helv=
etica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direction: ltr; al=
ign-self: start; text-indent: 0px; margin: 0px 0px 0.25em;">
<span role=3D"presentation" style=3D"font-family: Consolas, "Courier N=
ew", monospace;"><code style=3D"font-family: Consolas, "Courier N=
ew", monospace;">clamd.conf</code></span> option:
<span role=3D"presentation" style=3D"font-family: Consolas, "Courier N=
ew", monospace;">
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
JsonStoreExtraHashes</code></span> (default 'no')</li></ul>
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
The file hash is now stored as "sha2-256" instead of "FileMD=
5". If you enable the "extra hashes" option, then it will al=
so record "md5" and "sha1".</div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Each object scanned now has a unique "Object ID".</div>
</li></ul>
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Sigtool: Renamed the sigtool option <span style=3D"font-family: Consolas, &=
quot;Courier New", monospace;">
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
--sha256</code></span> to
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
--sha2-256</code></span>. The original option is still functional but is de=
precated.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWA9b3539fd-970a-47b1-d=
0a0-cccc261995c0" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li></ul>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin: 24px 0px 16px; font-family: Aptos, Aptos_EmbeddedFont, Ap=
tos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: =
rgb(0, 0, 0);" class=3D"elementToProof" id=3D"other-improvements">
<b>Other improvements</b></div>
<ul style=3D"direction: ltr; text-align: left; margin: 0px 0px 0.7em; paddi=
ng-right: 2.5em; padding-left: 2.5em; list-style-position: initial; list-st=
yle-type: disc;" data-line=3D"420">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Set a limit on the max-recursion config option. Users will no longer be abl=
e to set max-recursion higher than 100. This change prevents errors on star=
t up or crashes if encountering a file with that many layers of recursion.<=
/div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1264" class=3D"OWAAutoLink" id=3D"OWA3c13d5c6-2912-10cc-3=
1b9-06e0f784edc1" href=3D"https://github.com/Cisco-Talos/clamav/pull/1264">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Build system: CMake improvements to support compiling for the AIX platform.=
This change is courtesy of GitHub user KamathForAIX.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1387" class=3D"OWAAutoLink" id=3D"OWAcb3fe27d-2a21-0b95-6=
a12-69ed37a5ecbf" href=3D"https://github.com/Cisco-Talos/clamav/pull/1387">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Improve support for extracting malformed zip archives. This change is court=
esy of Frederick Sell.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1460" class=3D"OWAAutoLink" id=3D"OWA2bcaf055-aa27-002f-4=
41d-4f1e16b8de11" href=3D"https://github.com/Cisco-Talos/clamav/pull/1460">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Windows: Code quality improvement for the ClamScan and ClamDScan <span styl=
e=3D"font-family: Consolas, "Courier New", monospace;">
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
--move</code></span> and
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
--remove</code></span> options. This change is courtesy of Maxim Suhan=
ov.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1470" class=3D"OWAAutoLink" id=3D"OWA9d01600b-bf5f-4ecd-5=
fe8-2cac776c02e4" href=3D"https://github.com/Cisco-Talos/clamav/pull/1470">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Added file type recognition for an initial set of AI model file types.</div=
>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
The file type is accessible to applications using libclamav via the scan ca=
llback functions and as an optional output parameter to the scan functions:
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
cl_scanfile_ex()</code></span>,
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
cl_scanmap_ex()</code></span>, and
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
cl_scandesc_ex()</code></span>.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
When scanning these files, type will now show "CL_TYPE_AI_MODEL" =
instead of "CL_TYPE_BINARY_DATA".</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1476" class=3D"OWAAutoLink" id=3D"OWA4111942d-456d-7e8e-9=
242-46f7a9e5afb2" href=3D"https://github.com/Cisco-Talos/clamav/pull/1476">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Added support for inline comments in ClamAV configuration files. This chang=
e is courtesy of GitHub user userwiths.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1308" class=3D"OWAAutoLink" id=3D"OWA9464f40a-295e-0c47-c=
f4e-cae32e8ef9b4" href=3D"https://github.com/Cisco-Talos/clamav/pull/1308">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Disabled the MyDoom hardcoded/heuristic detection because of false positive=
s.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1495" class=3D"OWAAutoLink" id=3D"OWA6b7582ac-7854-5453-5=
c5f-17693d3135c0" href=3D"https://github.com/Cisco-Talos/clamav/pull/1495">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Sigtool: Added support for creating <span style=3D"font-family: Consolas, &=
quot;Courier New", monospace;">
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
.cdiff</code></span> and
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
.script</code></span> patch files for CVDs that have underscores in th=
e CVD name. Also improved support for relative paths with the
<span style=3D"font-family: Consolas, "Courier New", monospace;">=
<code style=3D"font-family: Consolas, "Courier New", monospace;">=
--diff</code></span> command.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1541" class=3D"OWAAutoLink" id=3D"OWAf26094e1-7cd7-6962-c=
2b8-8b2b096cf08f" href=3D"https://github.com/Cisco-Talos/clamav/pull/1541">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Windows: Improved support for file names with UTF-8 characters not found in=
the ANSI or OEM code pages when printing scan results or showing activity =
in the ClamDTOP monitoring utility. Fixed a bug with opening files with suc=
h names with the Sigtool utility.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1461" class=3D"OWAAutoLink" id=3D"OWA5bdc9dd9-fad1-b957-b=
2df-38f96c7934b7" href=3D"https://github.com/Cisco-Talos/clamav/pull/1461">=
GitHub pull request #1</a></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1537" class=3D"OWAAutoLink" id=3D"OWA276e8337-7391-f2a7-9=
d26-c1adc8e2f53d" href=3D"https://github.com/Cisco-Talos/clamav/pull/1537">=
GitHub pull request #2</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Improved the code quality of the ZIP module. Added inline documentation.</d=
iv>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1548" class=3D"OWAAutoLink" id=3D"OWA01af6715-9a02-38c8-2=
264-12af8951b2d2" href=3D"https://github.com/Cisco-Talos/clamav/pull/1548">=
GitHub pull request #1</a></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1552" class=3D"OWAAutoLink" id=3D"OWA080a9607-3f41-7bf2-3=
683-75135568b0ee" href=3D"https://github.com/Cisco-Talos/clamav/pull/1552">=
GitHub pull request #2</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Always run scan callbacks for embedded files. Embedded files are found with=
in other files through signature matches instead of by parsing. They will n=
ow be processed the same way and then they can trigger application callback=
s (e.g., "pre-scan", "post-scan",
etc.).</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
This change will impact scans with both the "leave-temps" feature=
and the "force-to-disk" feature enabled, resulting in additional=
temporary files.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWAa6bfd472-fff7-ba1e-e=
f79-2fb7b13b171f" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Added DevContainer templates to the ClamAV Git repository in order to make =
it easier to set up AlmaLinux or Debian development environments.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1462" class=3D"OWAAutoLink" id=3D"OWAeac2ac24-962c-ea25-4=
d3f-e9d9384f0fa1" href=3D"https://github.com/Cisco-Talos/clamav/pull/1462">=
GitHub pull request</a></div>
</li></ul>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin: 24px 0px 16px; font-family: Aptos, Aptos_EmbeddedFont, Ap=
tos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: =
rgb(0, 0, 0);" class=3D"elementToProof" id=3D"bug-fixes">
<b>Bug fixes</b></div>
<ul style=3D"direction: ltr; text-align: left; margin: 0px 0px 0.7em; paddi=
ng-right: 2.5em; padding-left: 2.5em; list-style-position: initial; list-st=
yle-type: disc;" data-line=3D"501">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Reduced email multipart message parser complexity.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1347" class=3D"OWAAutoLink" id=3D"OWAb2f1fffe-7b54-ee0a-1=
fdf-9eed6fe507b8" href=3D"https://github.com/Cisco-Talos/clamav/pull/1347">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Fixed possible undefined behavior in inflate64 module. The inflate64 module=
is a modified version of the zlib library, taken from version 1.2.3 with s=
ome customization and with some cherry-picked fixes. This adds one addition=
al fix from zlib 1.2.9. Thank you
to TITAN Team for reporting this issue.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1469" class=3D"OWAAutoLink" id=3D"OWA4f264ad1-e7fe-d507-e=
955-86ed2c6e5198" href=3D"https://github.com/Cisco-Talos/clamav/pull/1469">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Fixed a bug in ClamD that broke reporting of memory usage on Linux. The STA=
TS command can be used to monitor ClamD directly or through ClamDTOP. The m=
emory stats feature does not work on all platforms (e.g., Windows).</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1465" class=3D"OWAAutoLink" id=3D"OWA469e69d0-56c0-4cc5-6=
85d-c876b4886152" href=3D"https://github.com/Cisco-Talos/clamav/pull/1465">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Windows: Fixed a build issue when the same library dependency is found in t=
wo different locations.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1453" class=3D"OWAAutoLink" id=3D"OWA39e46d41-7c04-6eb6-2=
c44-ac86b12fbae2" href=3D"https://github.com/Cisco-Talos/clamav/pull/1453">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Fixed an infinite loop when scanning some email files in debug-mode. This f=
ix is courtesy of Yoann Lecuyer.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1445" class=3D"OWAAutoLink" id=3D"OWAce6c0913-219e-047d-7=
53d-cd68f0662737" href=3D"https://github.com/Cisco-Talos/clamav/pull/1445">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Fixed a stack buffer overflow bug in the phishing signature load process. T=
his fix is courtesy of GitHub user Shivam7-1.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1486" class=3D"OWAAutoLink" id=3D"OWA42eceebe-2ddb-4dc0-0=
ba1-624b37ac1e82" href=3D"https://github.com/Cisco-Talos/clamav/pull/1486">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Fixed a race condition in the Freshclam feature tests. This fix is courtesy=
of GitHub user rma-x.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1513" class=3D"OWAAutoLink" id=3D"OWA41e899d6-8785-fb66-a=
c31-e5603031dc73" href=3D"https://github.com/Cisco-Talos/clamav/pull/1513">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Windows: Fixed a 5-byte heap buffer overread in the Windows unit tests. Thi=
s fix is courtesy of GitHub user Sophie0x2E.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1542" class=3D"OWAAutoLink" id=3D"OWA8ade4dde-1ba1-5737-8=
5ea-773519df9e3d" href=3D"https://github.com/Cisco-Talos/clamav/pull/1542">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Fix double-extraction of OOXML-based office documents.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWA69861e15-9e8a-1202-d=
25b-52109369e442" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
ClamBC: Fixed crashes on startup.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWA8b7ea716-560e-679d-b=
d98-52c08bb21a4f" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li></ul>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin: 24px 0px 16px; font-family: Aptos, Aptos_EmbeddedFont, Ap=
tos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: =
rgb(0, 0, 0);" class=3D"elementToProof" id=3D"acknowledgments">
<b>Acknowledgments</b></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin: 0=
px 0px 16px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class=
=3D"elementToProof">
Special thanks to the following people for code contributions and bug repor=
ts:</div>
<ul style=3D"direction: ltr; text-align: left; margin: 0px 0px 0.7em; paddi=
ng-right: 2.5em; padding-left: 2.5em; list-style-position: initial; list-st=
yle-type: disc; flex-direction: column; display: flex;" data-line=3D"555">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; align-self: start; text-indent: 0px; margin: 0px 0px 0.25em;">
b1tg</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontS=
ervice, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0=
); direction: ltr; align-self: start; text-indent: 0px; margin: 0px 0px 0.2=
5em;">
ChaoticByte</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_=
MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(=
0, 0, 0); direction: ltr; align-self: start; text-indent: 0px; margin: 0px =
0px 0.25em;">
Frederick Sell</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Apt=
os_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: r=
gb(0, 0, 0); direction: ltr; align-self: start; text-indent: 0px; margin: 0=
px 0px 0.25em;">
KamathForAIX</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos=
_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb=
(0, 0, 0); direction: ltr; align-self: start; text-indent: 0px; margin: 0px=
0px 0.25em;">
Mark Carey at SAP</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, =
Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color=
: rgb(0, 0, 0); direction: ltr; align-self: start; text-indent: 0px; margin=
: 0px 0px 0.25em;">
Maxim Suhanov</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Apto=
s_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rg=
b(0, 0, 0); direction: ltr; align-self: start; text-indent: 0px; margin: 0p=
x 0px 0.25em;">
rma-x</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFont=
Service, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, =
0); direction: ltr; align-self: start; text-indent: 0px; margin: 0px 0px 0.=
25em;">
Shivam7-1</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MS=
FontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0,=
0, 0); direction: ltr; align-self: start; text-indent: 0px; margin: 0px 0p=
x 0.25em;">
Sophie0x2E</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_M=
SFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0=
, 0, 0); direction: ltr; align-self: start; text-indent: 0px; margin: 0px 0=
px 0.25em;">
TITAN Team</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_M=
SFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0=
, 0, 0); direction: ltr; align-self: start; text-indent: 0px; margin: 0px 0=
px 0.25em;">
userwiths</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MS=
FontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0,=
0, 0); direction: ltr; align-self: start; text-indent: 0px; margin: 0px 0p=
x 0.25em;">
Yoann Lecuyer</li></ul>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
<br>
</div>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
<br>
</div>
<div id=3D"Signature">
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0);">
Respectfully,</div>
<div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0);">
Val</div>
<div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0);">
<br>
<span style=3D"font-family: Helvetica; font-size: 12px;">Valerie Snyder (sh=
e/they)</span><br>
<span style=3D"font-family: Helvetica; font-size: 12px;">ClamAV Development=
</span><br>
<span style=3D"font-family: Helvetica; font-size: 12px;">Talos</span><br>
<span style=3D"font-family: Helvetica; font-size: 12px;">Cisco Systems, Inc=
.</span><br>
</div>
</div>
</body>
</html>
--_000_CH3PR11MB8750A6128542C2A00A343393C633ACH3PR11MB8750namp_--
--===============5516589023394447032==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
clamav-announce mailing list
[email protected]
https://lists.clamav.net/mailman/listinfo/clamav-announce
http://www.clamav.net/contact.html#ml
--===============5516589023394447032==--