ClamAV 1.5.0 now available!
"Val Snyder \(micasnyd\) via clamav-announce" <[email protected]> Tue, 7 Oct 2025 14:26:01 +0000
| Newsgroups | gmane.comp.security.virus.clamav.announce |
|---|---|
| Message-ID | <CH3PR11MB87501812051B3417B51CBB1EC6E0A__39132.5036458269$1759847483$gmane$org@CH3PR11MB8750.namprd11.prod.outlook.com> |
--===============8638913628983763905==
Content-Language: en-US
Content-Type: multipart/alternative;
boundary="_000_CH3PR11MB87501812051B3417B51CBB1EC6E0ACH3PR11MB8750namp_"
--_000_CH3PR11MB87501812051B3417B51CBB1EC6E0ACH3PR11MB8750namp_
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable
Read this online at https://blog.clamav.net/2025/10/clamav-150-released.htm=
l
The ClamAV 1.5.0 is now available. You may find the source code and install=
ers for this release at clamav.net/downloads<https://www.clamav.net/downloa=
ds> or on the ClamAV GitHub release page<https://github.com/Cisco-Talos/cla=
mav/releases/tag/clamav-1.5.0>.
IMPORTANT: A major feature of the 1.5 release is a FIPS-mode compatible met=
hod for verifying the authenticity of CVD signature database archives and C=
DIFF signature database patch files. This feature relies on =93.cvd.sign=94=
signature files for the daily, main, and bytecode databases. The Freshclam=
with 1.5.0 will download these files as will the latest version of CVDUpda=
te. When they are not present, ClamAV will fall back to using the legacy MD=
5-based RSA signature check.
Tip: If you are downloading the source from the GitHub release page, the pa=
ckage labeled "clamav-1.5.0.tar.gz" does not require an internet connection=
to build. All dependencies are included in this package. However, if you d=
ownload the ZIP or TAR.GZ generated by GitHub, located at the very bottom, =
then an internet connection will be required during the build to download a=
dditional Rust dependencies.
ClamAV 1.5.0 includes the following improvements and changes:
Major changes
*
Added checks to determine if an OLE2-based Microsoft Office document is enc=
rypted.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1295>
*
Added the ability to record URIs found in HTML if the generate-JSON-metadat=
a feature is enabled. Also adds an option to disable this in case you want =
the JSON metadata feature but do not want to record HTML URIs. The ClamScan=
command-line option is --json-store-html-uris=3Dno. The clamd.conf config =
option is JsonStoreHTMLURIs no. The libclamav general scan option is CL_SCA=
N_GENERAL_STORE_HTML_URIS
GitHub pull request #1<https://github.com/Cisco-Talos/clamav/pull/1281>
GitHub pull request #2<https://github.com/Cisco-Talos/clamav/pull/1482>
GitHub pull request #3<https://github.com/Cisco-Talos/clamav/pull/1514>
*
Added the ability to record URIs found in PDFs if the generate-JSON-metadat=
a feature is enabled. Also adds an option to disable this in case you want =
the JSON metadata feature but do not want to record PDF URIs. The ClamScan =
command-line option is --json-store-pdf-uris=3Dno. The clamd.conf config op=
tion is JsonStorePDFURIs no. The libclamav general scan option is CL_SCAN_G=
ENERAL_STORE_PDF_URIS
GitHub pull request #1<https://github.com/Cisco-Talos/clamav/pull/1482>
GitHub pull request #2<https://github.com/Cisco-Talos/clamav/pull/1514>
GitHub pull request #3<https://github.com/Cisco-Talos/clamav/pull/1559>
GitHub pull request #4<https://github.com/Cisco-Talos/clamav/pull/1572>
*
Added regex support for the clamd.conf OnAccessExcludePath config option. T=
his change courtesy of GitHub user b1tg.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1314>
*
Added CVD signing/verification with external .sign files.
Freshclam will now attempt to download external signature files to accompan=
y existing .cvd databases and .cdiff patch files. Sigtool now has commands =
to sign and verify using the external signatures.
ClamAV now installs a 'certs' directory in the app config directory (e.g., =
<prefix>/etc/certs). The install path is configurable. The CMake option to =
configure the CVD certs directory is -D CVD_CERTS_DIRECTORY=3DPATH
New options to set an alternative CVD certs directory:
Added two new APIs to the public clamav.h header:
cl_error_t cl_cvdverify_ex(
const char *file,
const char *certs_directory,
uint32_t dboptions);
cl_error_t cl_cvdunpack_ex(
const char *file,
const char *dir,
const char *certs_directory,
uint32_t dboptions);
The original cl_cvdverify and cl_cvdunpack are deprecated.
Added a cl_engine_field enum option CL_ENGINE_CVDCERTSDIR. You may set this=
option with cl_engine_set_str and get it with cl_engine_get_str, to overri=
de the compiled in default CVD certs directory.
Thank you to Mark Carey at SAP for inspiring work on this feature with an i=
nitial proof of concept for external-signature FIPS compliant CVD signing.
GitHub pull request #1<https://github.com/Cisco-Talos/clamav/pull/1417>
GitHub pull request #2<https://github.com/Cisco-Talos/clamav/pull/1478>
GitHub pull request #3<https://github.com/Cisco-Talos/clamav/pull/1489>
GitHub pull request #4<https://github.com/Cisco-Talos/clamav/pull/1491>
* The command-line option for Freshclam, ClamD, ClamScan, and Sigtoo=
l is --cvdcertsdir PATH
* The environment variable for Freshclam, ClamD, ClamScan, and Sigto=
ol is CVD_CERTS_DIR
* The config option for Freshclam and ClamD is CVDCertsDirectory PAT=
H
*
Freshclam, ClamD, ClamScan, and Sigtool: Added an option to enable FIPS-lik=
e limits disabling MD5 and SHA1 from being used for verifying digital signa=
tures or for being used to trust a file when checking for false positives (=
FPs).
For freshclam.conf and clamd.conf set this config option:
FIPSCryptoHashLimits yes
For clamscan and sigtool use this command-line option:
--fips-limits
For libclamav: Enable FIPS-limits for a ClamAV engine like this:
cl_engine_set_num(engine, CL_ENGINE_FIPS_LIMITS, 1);
ClamAV will also attempt to detect if FIPS-mode is enabled. If so, it will =
automatically enable the FIPS-limits feature.
This change mitigates safety concerns over the use of MD5 and SHA1 algorith=
ms to trust files and is required to enable ClamAV to operate legitimately =
in FIPS-mode enabled environments.
Note: ClamAV may still calculate MD5 or SHA1 hashes as needed for detection=
purposes or for informational purposes in FIPS-enabled environments and wh=
en the FIPS-limits option is enabled.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
*
Upgraded the clean-file scan cache to use SHA2-256 (prior versions use MD5)=
. The clean-file cache algorithm is not configurable.
This change resolves safety concerns over the use of MD5 to trust files and=
is required to enable ClamAV to operate legitimately in FIPS-mode enabled =
environments.
GitHub pull request #1<https://github.com/Cisco-Talos/clamav/pull/1532>
GitHub pull request #2<https://github.com/Cisco-Talos/clamav/pull/1560>
*
ClamD: Added an option to disable select administrative commands including =
SHUTDOWN, RELOAD, STATS and VERSION.
The new clamd.conf options are:
EnableShutdownCommand yes
EnableReloadCommand yes
EnableStatsCommand yes
EnableVersionCommand yes
This change courtesy of GitHub user ChaoticByte.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1502>
*
libclamav: Added extended hashing functions with a "flags" parameter that a=
llows the caller to choose if they want to bypass FIPS hash algorithm limit=
s:
cl_error_t cl_hash_data_ex(
const char *alg,
const uint8_t *data,
size_t data_len,
uint8_t **hash,
size_t *hash_len,
uint32_t flags);
cl_error_t cl_hash_init_ex(
const char *alg,
uint32_t flags,
cl_hash_ctx_t **ctx_out);
cl_error_t cl_update_hash_ex(
cl_hash_ctx_t *ctx,
const uint8_t *data,
size_t length);
cl_error_t cl_finish_hash_ex(
cl_hash_ctx_t *ctx,
uint8_t **hash,
size_t *hash_len,
uint32_t flags);
void cl_hash_destroy(void *ctx);
cl_error_t cl_hash_file_fd_ex(
const char *alg,
int fd,
size_t offset,
size_t length,
uint8_t **hash,
size_t *hash_len,
uint32_t flags);
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
*
ClamScan: Improved the precision of the bytes-scanned and bytes-read counte=
rs. The ClamScan scan summary will now report exact counts in "GiB", "MiB",=
"KiB", or "B" as appropriate. Previously, it always reported "MB".
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
*
ClamScan: Add hash & file-type in/out CLI options:
We will not be adding this for ClamDScan, as we do not have a mechanism in =
the ClamD socket API to receive scan options or a way for ClamD to include =
scan metadata in the response.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
* --hash-hint: The file hash so that libclamav does not need to calc=
ulate it. The type of hash must match the --hash-alg.
* --log-hash: Print the file hash after each file scanned. The type =
of hash printed will match the --hash-alg.
* --hash-alg: The hashing algorithm used for either --hash-hint or -=
-log-hash. Supported algorithms are "md5", "sha1", "sha2-256". If not speci=
fied, the default is "sha2-256".
* --file-type-hint: The file type hint so that libclamav can optimiz=
e scanning (e.g., "pe", "elf", "zip", etc.). You may also use ClamAV type n=
ames such as "CL_TYPE_PE". ClamAV will ignore the hint if it is not familia=
r with the specified type. See also: https://docs.clamav.net/appendix/FileT=
ypes.html#file-types
* --log-file-type: Print the file type after each file scanned.
*
libclamav: Added new scan functions that provide additional functionality:
cl_error_t cl_scanfile_ex(
const char *filename,
cl_verdict_t *verdict_out,
const char **last_alert_out,
uint64_t *scanned_out,
const struct cl_engine *engine,
struct cl_scan_options *scanoptions,
void *context,
const char *hash_hint,
char **hash_out,
const char *hash_alg,
const char *file_type_hint,
char **file_type_out);
cl_error_t cl_scandesc_ex(
int desc,
const char *filename,
cl_verdict_t *verdict_out,
const char **last_alert_out,
uint64_t *scanned_out,
const struct cl_engine *engine,
struct cl_scan_options *scanoptions,
void *context,
const char *hash_hint,
char **hash_out,
const char *hash_alg,
const char *file_type_hint,
char **file_type_out);
cl_error_t cl_scanmap_ex(
cl_fmap_t *map,
const char *filename,
cl_verdict_t *verdict_out,
const char **last_alert_out,
uint64_t *scanned_out,
const struct cl_engine *engine,
struct cl_scan_options *scanoptions,
void *context,
const char *hash_hint,
char **hash_out,
const char *hash_alg,
const char *file_type_hint,
char **file_type_out);
The older cl_scan*() functions are now deprecated and may be removed in a f=
uture release. See clamav.h for more details.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
*
libclamav: Added a new engine option to toggle temp directory recursion.
Temp directory recursion is the idea that each object scanned in ClamAV's r=
ecursive extract/scan process will get a new temp subdirectory, mimicking t=
he nesting structure of the file.
Temp directory recursion was introduced in ClamAV 0.103 and is enabled when=
ever --leave-temps / LeaveTemporaryFiles is enabled.
In ClamAV 1.5, an application linking to libclamav can separately enable te=
mp directory recursion if they wish. For ClamScan and ClamD, it will remain=
tied to --leave-temps / LeaveTemporaryFiles options.
The new temp directory recursion option can be enabled with:
cl_engine_set_num(engine, CL_ENGINE_TMPDIR_RECURSION, 1);
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
*
libclamav: Added a class of scan callback functions that can be added with =
the following API function:
void cl_engine_set_scan_callback(struct cl_engine *engine, clcb_scan callba=
ck, cl_scan_callback_t location);
The scan callback location may be configured using the following five value=
s:
Each callback may alter scan behavior using the following return codes:
Each callback is given a pointer to the current scan layer from which they =
can get previous layers, can get the layer's fmap, and then various attribu=
tes of the layer and of the fmap. To make this possible, there are new APIs=
to query scan-layer details and fmap details:
cl_error_t cl_fmap_set_name(cl_fmap_t *map, const char *name);
cl_error_t cl_fmap_get_name(cl_fmap_t *map, const char **name_out);
cl_error_t cl_fmap_set_path(cl_fmap_t *map, const char *path);
cl_error_t cl_fmap_get_path(cl_fmap_t *map, const char **path_out, size_t=
*offset_out, size_t *len_out);
cl_error_t cl_fmap_get_fd(const cl_fmap_t *map, int *fd_out, size_t *offs=
et_out, size_t *len_out);
cl_error_t cl_fmap_get_size(const cl_fmap_t *map, size_t *size_out);
cl_error_t cl_fmap_set_hash(const cl_fmap_t *map, const char *hash_alg, c=
har hash);
cl_error_t cl_fmap_have_hash(const cl_fmap_t *map, const char *hash_alg, =
bool *have_hash_out);
cl_error_t cl_fmap_will_need_hash_later(const cl_fmap_t *map, const char =
*hash_alg);
cl_error_t cl_fmap_get_hash(const cl_fmap_t *map, const char *hash_alg, c=
har **hash_out);
cl_error_t cl_fmap_get_data(const cl_fmap_t *map, size_t offset, size_t l=
en, const uint8_t **data_out, size_t *data_len_out);
cl_error_t cl_scan_layer_get_fmap(cl_scan_layer_t *layer, cl_fmap_t **fma=
p_out);
cl_error_t cl_scan_layer_get_parent_layer(cl_scan_layer_t *layer, cl_scan=
_layer_t **parent_layer_out);
cl_error_t cl_scan_layer_get_type(cl_scan_layer_t *layer, const char **ty=
pe_out);
cl_error_t cl_scan_layer_get_recursion_level(cl_scan_layer_t *layer, uint=
32_t *recursion_level_out);
cl_error_t cl_scan_layer_get_object_id(cl_scan_layer_t *layer, uint64_t *=
object_id_out);
cl_error_t cl_scan_layer_get_last_alert(cl_scan_layer_t *layer, const cha=
r **alert_name_out);
cl_error_t cl_scan_layer_get_attributes(cl_scan_layer_t *layer, uint32_t =
*attributes_out);
This deprecates, but does not immediately remove, the existing scan callbac=
ks:
void cl_engine_set_clcb_pre_cache(struct cl_engine *engine, clcb_pre_cach=
e callback);
void cl_engine_set_clcb_file_inspection(struct cl_engine *engine, clcb_fi=
le_inspection callback);
void cl_engine_set_clcb_pre_scan(struct cl_engine *engine, clcb_pre_scan =
callback);
void cl_engine_set_clcb_post_scan(struct cl_engine *engine, clcb_post_sca=
n callback);
void cl_engine_set_clcb_virus_found(struct cl_engine *engine, clcb_virus_=
found callback);
void cl_engine_set_clcb_hash(struct cl_engine *engine, clcb_hash callback=
);
There is an interactive test program to demonstrate the new callbacks. See:=
examples/ex_scan_callbacks.c
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
* CL_SCAN_CALLBACK_PRE_HASH: Occurs just after basic file-type detec=
tion and before any hashes have been calculated either for the cache or the=
gen-json metadata.
* CL_SCAN_CALLBACK_PRE_SCAN: Occurs before parser modules run and be=
fore pattern matching.
* CL_SCAN_CALLBACK_POST_SCAN: Occurs after pattern matching and afte=
r running parser modules. A.k.a. the scan is complete for this layer.
* CL_SCAN_CALLBACK_ALERT: Occurs each time an alert (detection) woul=
d be triggered during a scan.
* CL_SCAN_CALLBACK_FILE_TYPE: Occurs each time the file type determi=
nation is refined. This may happen more than once per layer.
*
CL_BREAK: Scan aborted by callback. The rest of the scan is skipped. This d=
oes not mark the file as clean or infected, it just skips the rest of the s=
can.
*
CL_SUCCESS / CL_CLEAN: File scan will continue.
For CL_SCAN_CALLBACK_ALERT: This means you want to ignore this specific ale=
rt and keep scanning.
This is different than CL_VERIFIED because it does not affect prior or futu=
re alerts. Return CL_VERIFIED instead if you want to remove prior alerts fo=
r this layer and skip the rest of the scan for this layer.
*
CL_VIRUS: This means you do not trust the file. A new alert will be added.
For CL_SCAN_CALLBACK_ALERT: This means you agree with the alert and no extr=
a alert is needed.
*
CL_VERIFIED: Layer explicitly trusted by the callback and previous alerts r=
emoved for THIS layer. You might want to do this if you trust the hash or v=
erified a digital signature. The rest of the scan will be skipped for THIS =
layer. For contained files, this does NOT mean that the parent or adjacent =
layers are trusted.
*
Signature names that start with "Weak." will no longer alert. Instead, they=
will be tracked internally and can be found in scan metadata JSON. This is=
a step towards enabling alerting signatures to depend on prior Weak indica=
tor matches in the current layer or in child layers.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
*
For the "Generate Metadata JSON" feature:
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
*
The "Viruses" array of alert names has been replaced by two new arrays that=
include additional details beyond just signature name:
* "Indicators" records three types of indicators:
* Strong indicators are for traditional alerting signature mat=
ches and will halt the scan, except in all-match mode.
* Potentially Unwanted indicators will only cause an alert at =
the end of the scan unless a Strong indicator is found. They are treated th=
e same as Strong indicators in all-match mode.
* Weak indicators do not alert and will be leveraged in a futu=
re version as a condition for logical signature matches.
* "Alerts" records only alerting indicators. Events that trust a =
file, such as false positive signatures, will remove affected indicators, a=
nd mark them as "Ignored" in the "Indicators" array.
*
Add new option to calculate and record additional hash types when the "gene=
rate metadata JSON" feature is enabled:
* libclamav option: CL_SCAN_GENERAL_STORE_EXTRA_HASHES
* ClamScan option: --json-store-extra-hashes (default off)
* clamd.conf option: JsonStoreExtraHashes (default 'no')
*
The file hash is now stored as "sha2-256" instead of "FileMD5". If you enab=
le the "extra hashes" option, then it will also record "md5" and "sha1".
*
Each object scanned now has a unique "Object ID".
*
Sigtool: Renamed the sigtool option --sha256 to --sha2-256. The original op=
tion is still functional but is deprecated.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
Other improvements
*
Set a limit on the max-recursion config option. Users will no longer be abl=
e to set max-recursion higher than 100. This change prevents errors on star=
t up or crashes if encountering a file with that many layers of recursion.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1264>
*
Build system: CMake improvements to support compiling for the AIX platform.=
This change is courtesy of GitHub user KamathForAIX.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1387>
*
Improve support for extracting malformed zip archives. This change is court=
esy of Frederick Sell.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1460>
*
Windows: Code quality improvement for the ClamScan and ClamDScan --move and=
--remove options. This change is courtesy of Maxim Suhanov.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1470>
*
Added file type recognition for an initial set of AI model file types.
The file type is accessible to applications using libclamav via the scan ca=
llback functions and as an optional output parameter to the scan functions:=
cl_scanfile_ex(), cl_scanmap_ex(), and cl_scandesc_ex().
When scanning these files, type will now show "CL_TYPE_AI_MODEL" instead of=
"CL_TYPE_BINARY_DATA".
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1476>
*
Added support for inline comments in ClamAV configuration files. This chang=
e is courtesy of GitHub user userwiths.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1308>
*
Disabled the MyDoom hardcoded/heuristic detection because of false positive=
s.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1495>
*
Sigtool: Added support for creating .cdiff and .script patch files for CVDs=
that have underscores in the CVD name. Also improved support for relative =
paths with the --diff command.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1541>
*
Windows: Improved support for file names with UTF-8 characters not found in=
the ANSI or OEM code pages when printing scan results or showing activity =
in the ClamDTOP monitoring utility. Fixed a bug with opening files with suc=
h names with the Sigtool utility.
GitHub pull request #1<https://github.com/Cisco-Talos/clamav/pull/1461>
GitHub pull request #2<https://github.com/Cisco-Talos/clamav/pull/1537>
*
Improved the code quality of the ZIP module. Added inline documentation.
GitHub pull request #1<https://github.com/Cisco-Talos/clamav/pull/1548>
GitHub pull request #2<https://github.com/Cisco-Talos/clamav/pull/1552>
*
Always run scan callbacks for embedded files. Embedded files are found with=
in other files through signature matches instead of by parsing. They will n=
ow be processed the same way and then they can trigger application callback=
s (e.g., "pre-scan", "post-scan", etc.).
A consequence of this change is that each embedded file will be pattern- ma=
tched just like any other extracted file. To minimize excessive pattern mat=
ching, file header validation checks were added for ZIP, ARJ, and CAB. Also=
fixed a bug with embedded PE file scanning to reduce unnecessary matching.
This change will impact scans with both the "leave-temps" feature and the "=
force-to-disk" feature enabled, resulting in additional temporary files.
GitHub pull request #1<https://github.com/Cisco-Talos/clamav/pull/1532>
GitHub pull request #2<https://github.com/Cisco-Talos/clamav/pull/1571>
*
Added DevContainer templates to the ClamAV Git repository in order to make =
it easier to set up AlmaLinux or Debian development environments.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1462>
*
Removed the "Heuristics.XZ.DicSizeLimit" alert because of potential uninten=
ded alerts based on system state.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1573>
*
Improved support for compiling on Solaris.
This fix courtesy of Andrew Watkins.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1569>
*
Improved support for compiling on GNU/Hurd.
This fix courtesy of Pino Toscano.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1569>
*
Improved support for linking with the NCurses library dependency when libti=
nfo is built as a separate library.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1356>
Bug fixes
*
Reduced email multipart message parser complexity.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1347>
*
Fixed possible undefined behavior in inflate64 module. The inflate64 module=
is a modified version of the zlib library, taken from version 1.2.3 with s=
ome customization and with some cherry-picked fixes. This adds one addition=
al fix from zlib 1.2.9. Thank you to TITAN Team for reporting this issue.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1469>
*
Fixed a bug in ClamD that broke reporting of memory usage on Linux. The STA=
TS command can be used to monitor ClamD directly or through ClamDTOP. The m=
emory stats feature does not work on all platforms (e.g., Windows).
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1465>
*
Windows: Fixed a build issue when the same library dependency is found in t=
wo different locations.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1453>
*
Fixed an infinite loop when scanning some email files in debug-mode. This f=
ix is courtesy of Yoann Lecuyer.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1445>
*
Fixed a stack buffer overflow bug in the phishing signature load process. T=
his fix is courtesy of GitHub user Shivam7-1.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1486>
*
Fixed a race condition in the Freshclam feature tests. This fix is courtesy=
of GitHub user rma-x.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1513>
*
Windows: Fixed a 5-byte heap buffer overread in the Windows unit tests. Thi=
s fix is courtesy of GitHub user Sophie0x2E.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1542>
*
Fix double-extraction of OOXML-based office documents.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
*
ClamBC: Fixed crashes on startup.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
*
Fixed an assortment of issues found with Coverity static analysis.
GitHub pull request #1<https://github.com/Cisco-Talos/clamav/pull/1574>
GitHub pull request #2<https://github.com/Cisco-Talos/clamav/pull/1582>
*
Fixed libclamav unit test, ClamD, and ClamDScan Valgrind test failures affe=
cting some platforms.
GitHub pull request #1<https://github.com/Cisco-Talos/clamav/pull/1554>
GitHub pull request #2<https://github.com/Cisco-Talos/clamav/pull/1570>
*
Fixed crash in the Sigtool program when using the --html-normalize option.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1556>
*
Fixed some potential NULL-pointer dereference issues if memory allocations =
fail.
Fix courtesy of GitHub user JiangJias.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1581>
Acknowledgments
Special thanks to the following people for code contributions and bug repor=
ts:
* Andrew Watkins
* b1tg
* ChaoticByte
* Frederick Sell
* KamathForAIX
* Mark Carey at SAP
* Maxim Suhanov
* Pino Toscano
* rma-x
* Shivam7-1
* Sophie0x2E
* TITAN Team
* userwiths
* Yoann Lecuyer
Valerie Snyder (she/they)
ClamAV Development
Talos
Cisco Systems, Inc.
--_000_CH3PR11MB87501812051B3417B51CBB1EC6E0ACH3PR11MB8750namp_
Content-Type: text/html; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable
<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1=
252">
<style type=3D"text/css" style=3D"display:none;"> P {margin-top:0;margin-bo=
ttom:0;} </style>
</head>
<body dir=3D"ltr">
<div style=3D"text-align: left; text-indent: 0px; margin-top: 1em; margin-b=
ottom: 1em; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Ca=
libri, Helvetica, sans-serif; font-size: 10pt; color: rgb(0, 0, 0);" class=
=3D"elementToProof">
<i>Read this online at <a class=3D"OWAAutoLink" id=3D"LPlnk543925" href=3D"=
https://blog.clamav.net/2025/10/clamav-150-released.html">
https://blog.clamav.net/2025/10/clamav-150-released.html</a></i></div>
<div style=3D"text-align: left; text-indent: 0px; margin-top: 1em; margin-b=
ottom: 1em; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Ca=
libri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class=
=3D"elementToProof">
<br>
</div>
<div style=3D"text-align: left; text-indent: 0px; margin-top: 1em; margin-b=
ottom: 1em; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Ca=
libri, Helvetica, sans-serif; font-size: 12pt;" class=3D"elementToProof">
<span style=3D"color: rgb(0, 0, 0);">The ClamAV 1.5.0 is now available=
. You may find the source code and installers for this release at
</span><span style=3D"color: rgb(70, 120, 134);"><u><a style=3D"color: rgb(=
70, 120, 134); margin: 0px;" rel=3D"noreferrer noopener" class=3D"Hyperlink=
SCXW232052544 BCX0 OWAAutoLink" id=3D"OWA6e88ad0b-2f43-4ce3-97df-810ad9fdf=
35a" target=3D"_blank" href=3D"https://www.clamav.net/downloads">clamav.net=
/downloads</a></u></span><span style=3D"color: rgb(0, 0, 0);"> or =
;on the
</span><span style=3D"color: rgb(70, 120, 134);"><u><a style=3D"color: rgb(=
70, 120, 134); margin: 0px;" rel=3D"noreferrer noopener" class=3D"Hyperlink=
SCXW232052544 BCX0 OWAAutoLink" id=3D"OWA737e2445-7fed-a46f-484c-ed5458086=
38d" target=3D"_blank" href=3D"https://github.com/Cisco-Talos/clamav/releas=
es/tag/clamav-1.5.0">ClamAV
GitHub release page</a></u></span><span style=3D"color: rgb(0, 0, 0);">.&n=
bsp;</span></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin: 1=
6px 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calib=
ri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class=3D"=
elementToProof">
<i>IMPORTANT: A major feature of the 1.5 release is a FIPS-mode c=
ompatible method for verifying the authenticity of CVD signature database a=
rchives and CDIFF signature database patch files. This feature relies on&nb=
sp;=93.cvd.sign=94 signature files for the daily, main,
and bytecode databases. The Freshclam with 1.5.0 will download these files=
as will the latest version of CVDUpdate. When they are not present, C=
lamAV will fall back to using the legacy MD5-based RSA signature check=
.</i></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin: 1=
6px 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calib=
ri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class=3D"=
elementToProof">
<i>Tip: If you are downloading the source from the GitHub release page, the=
package labeled "clamav-1.5.0.tar.gz" does not require an intern=
et connection to build. All dependencies are included in this package. Howe=
ver, if you download the ZIP or TAR.GZ generated
by GitHub, located at the very bottom, then an internet connection wi=
ll be required during the build to download additional Rust depen=
dencies.</i> </div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin: 0=
px 0px 16px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class=
=3D"elementToProof">
ClamAV 1.5.0 includes the following improvements and changes: </div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin: 24px 0px 16px; font-family: Aptos, Aptos_EmbeddedFont, Ap=
tos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: =
rgb(0, 0, 0);" class=3D"elementToProof" id=3D"major-changes">
<b>Major changes</b></div>
<ul style=3D"direction: ltr; text-align: left; margin: 0px 0px 0.7em; paddi=
ng-right: 2.5em; padding-left: 2.5em; list-style-position: initial; list-st=
yle-type: disc;" data-line=3D"11">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Added checks to determine if an OLE2-based Microsoft Office document is enc=
rypted.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1295" class=3D"OWAAutoLink" id=3D"OWA57886a75-0de0-f70c-8=
4af-688df45091b0" href=3D"https://github.com/Cisco-Talos/clamav/pull/1295">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Added the ability to record URIs found in HTML if the generate-JSON-metadat=
a feature is enabled. Also adds an option to disable this in case you want =
the JSON metadata feature but do not want to record HTML URIs. The ClamScan=
command-line option is
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">--json-store-html-uris=3Dno</code></span>. The
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">clamd.conf</code></span> config option is
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">JsonStoreHTMLURIs no</code></span>. The libclamav general scan op=
tion is
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">CL_SCAN_GENERAL_STORE_HTML_URIS</code></span></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1281" class=3D"OWAAutoLink" id=3D"OWA1f8de309-04c9-0082-1=
edf-db7cc4d10462" href=3D"https://github.com/Cisco-Talos/clamav/pull/1281">=
GitHub pull request #1</a></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1482" class=3D"OWAAutoLink" id=3D"OWA035c28d0-6fd7-1ec0-7=
045-41708415803d" href=3D"https://github.com/Cisco-Talos/clamav/pull/1482">=
GitHub pull request #2</a></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1514" class=3D"OWAAutoLink" id=3D"OWAfe087932-4bba-ec2a-5=
3ad-c2479427bfed" href=3D"https://github.com/Cisco-Talos/clamav/pull/1514">=
GitHub pull request #3</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Added the ability to record URIs found in PDFs if the generate-JSON-metadat=
a feature is enabled. Also adds an option to disable this in case you want =
the JSON metadata feature but do not want to record PDF URIs. The ClamScan =
command-line option is
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">--json-store-pdf-uris=3Dno</code></span>. The
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">clamd.conf</code></span> config option is
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">JsonStorePDFURIs no</code></span>. The libclamav general scan opt=
ion is
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">CL_SCAN_GENERAL_STORE_PDF_URIS</code></span></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1482" class=3D"OWAAutoLink" id=3D"OWA2b520dcd-9c04-b18b-a=
dc8-f2847c08ced6" href=3D"https://github.com/Cisco-Talos/clamav/pull/1482">=
GitHub pull request #1</a></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1514" class=3D"OWAAutoLink" id=3D"OWA4483fbe2-4bd4-76d8-2=
66e-1acff7a37902" href=3D"https://github.com/Cisco-Talos/clamav/pull/1514">=
GitHub pull request #2</a></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1559" class=3D"OWAAutoLink" id=3D"OWA247829c8-095b-7678-9=
52f-3885effd85fd" href=3D"https://github.com/Cisco-Talos/clamav/pull/1559">=
GitHub pull request #3</a></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1572" class=3D"OWAAutoLink" id=3D"OWA82adf942-cf95-b854-7=
4a2-7b9a235e1de7" href=3D"https://github.com/Cisco-Talos/clamav/pull/1572">=
GitHub pull request #4</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Added regex support for the <span style=3D"font-family: Menlo, Monaco, &quo=
t;Courier New", monospace;">
<code style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;">clamd.conf</code></span> <span style=3D"font-family: Menlo, Monac=
o, "Courier New", monospace;"><code style=3D"font-family: Menlo, =
Monaco, "Courier New", monospace;">OnAccessExcludePath</code></sp=
an> config
option. This change courtesy of GitHub user b1tg.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1314" class=3D"OWAAutoLink" id=3D"OWA0d38f13c-afe2-e4e1-0=
b33-7f8f0c5e0639" href=3D"https://github.com/Cisco-Talos/clamav/pull/1314">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Added CVD signing/verification with external <span style=3D"font-family: Me=
nlo, Monaco, "Courier New", monospace;">
<code style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;">.sign</code></span> files.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Freshclam will now attempt to download external signature files to accompan=
y existing
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">.cvd</code></span> databases and
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">.cdiff</code></span> patch files. Sigtool now has commands t=
o sign and verify using the external signatures.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
ClamAV now installs a 'certs' directory in the app config directory (e.g., =
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;">
<code style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><prefix>/etc/certs</code></span>). The install path is configura=
ble. The CMake option to configure the CVD certs directory is
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">-D CVD_CERTS_DIRECTORY=3DPATH</code></span></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
New options to set an alternative CVD certs directory:</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Added two new APIs to the public clamav.h header:</div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 1px; border-sty=
le: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D"p=
resentation" class=3D"elementToProof"><div style=3D"font-family: Menlo, Mon=
aco, "Courier New", monospace;" class=3D"elementToProof"><span st=
yle=3D"line-height: 1.357em;"><code style=3D"font-family: Menlo, Monaco, &q=
uot;Courier New", monospace; display: inline-block;">cl_error_t cl_cvd=
verify_ex(=0A=
const char *file,=0A=
const char *certs_directory,=0A=
uint32_t dboptions);=0A=
=0A=
cl_error_t cl_cvdunpack_ex(=0A=
const char *file,=0A=
const char *dir,=0A=
const char *certs_directory,=0A=
uint32_t dboptions);=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
The original <span style=3D"font-family: Menlo, Monaco, "Courier New&q=
uot;, monospace;">
<code style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;">cl_cvdverify</code></span> and
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">cl_cvdunpack</code></span> are deprecated.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Added a <span style=3D"font-family: Menlo, Monaco, "Courier New",=
monospace;"><code style=3D"font-family: Menlo, Monaco, "Courier New&q=
uot;, monospace;">cl_engine_field</code></span> enum option
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">CL_ENGINE_CVDCERTSDIR</code></span>. You may set this option with
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">cl_engine_set_str</code></span> and get it with
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">cl_engine_get_str</code></span>, to override the compiled in defa=
ult CVD certs directory.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Thank you to Mark Carey at SAP for inspiring work on this feature with an i=
nitial proof of concept for external-signature FIPS compliant CVD signing.<=
/div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1417" class=3D"OWAAutoLink" id=3D"OWAff190e90-93e7-b4bf-b=
1e7-f4259390d9b1" href=3D"https://github.com/Cisco-Talos/clamav/pull/1417">=
GitHub pull request #1</a></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1478" class=3D"OWAAutoLink" id=3D"OWA3e51b02e-b148-4e4f-1=
933-6625d4d3a10a" href=3D"https://github.com/Cisco-Talos/clamav/pull/1478">=
GitHub pull request #2</a></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1489" class=3D"OWAAutoLink" id=3D"OWA458bfda7-0d56-c453-1=
794-7b1eff320f52" href=3D"https://github.com/Cisco-Talos/clamav/pull/1489">=
GitHub pull request #3</a></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1491" class=3D"OWAAutoLink" id=3D"OWAc863151c-87c8-b0f1-8=
f70-048409d38a34" href=3D"https://github.com/Cisco-Talos/clamav/pull/1491">=
GitHub pull request #4</a></div>
</li><ul style=3D"direction: ltr; text-align: left; margin: 0px 0px 0.7em; =
padding-right: 2.5em; padding-left: 2.5em; list-style-position: initial; li=
st-style-type: disc; flex-direction: column; display: flex;" data-line=3D"6=
3">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; align-self: start; text-indent: 0px; line-height: 1.25; margin: 0=
px 0px 0.25em;">
The command-line option for Freshclam, ClamD, ClamScan, and Sigtool is <spa=
n role=3D"presentation" style=3D"font-family: Menlo, Monaco, "Courier =
New", monospace;">
<code style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;">--cvdcertsdir PATH</code></span></li><li style=3D"font-family: Aptos, =
Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; fo=
nt-size: 12pt; color: rgb(0, 0, 0); direction: ltr; align-self: start; text=
-indent: 0px; line-height: 1.25; margin: 0px 0px 0.25em;">
The environment variable for Freshclam, ClamD, ClamScan, and Sigtool is <sp=
an role=3D"presentation" style=3D"font-family: Menlo, Monaco, "Courier=
New", monospace;">
<code style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;">CVD_CERTS_DIR</code></span></li><li style=3D"font-family: Aptos, Aptos=
_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-si=
ze: 12pt; color: rgb(0, 0, 0); direction: ltr; align-self: start; text-inde=
nt: 0px; line-height: 1.25; margin: 0px 0px 0.25em;">
The config option for Freshclam and ClamD is <span role=3D"presentation" st=
yle=3D"font-family: Menlo, Monaco, "Courier New", monospace;">
<code style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;">CVDCertsDirectory PATH</code></span></li></ul>
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Freshclam, ClamD, ClamScan, and Sigtool: Added an option to enable FIPS-lik=
e limits disabling MD5 and SHA1 from being used for verifying digital signa=
tures or for being used to trust a file when checking for false positives (=
FPs).</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
For <span style=3D"font-family: Menlo, Monaco, "Courier New", mon=
ospace;"><code style=3D"font-family: Menlo, Monaco, "Courier New"=
, monospace;">freshclam.conf</code></span> and
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">clamd.conf</code></span> set this config option:</div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 1px; border-sty=
le: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D"p=
resentation" class=3D"elementToProof"><div style=3D"font-family: Menlo, Mon=
aco, "Courier New", monospace;" class=3D"elementToProof"><span st=
yle=3D"line-height: 1.357em;"><code style=3D"font-family: Menlo, Monaco, &q=
uot;Courier New", monospace; display: inline-block;">FIPSCryptoHashLim=
its yes=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
For <span style=3D"font-family: Menlo, Monaco, "Courier New", mon=
ospace;"><code style=3D"font-family: Menlo, Monaco, "Courier New"=
, monospace;">clamscan</code></span> and
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">sigtool</code></span> use this command-line option:</div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 1px; border-sty=
le: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D"p=
resentation" class=3D"elementToProof"><div style=3D"font-family: Menlo, Mon=
aco, "Courier New", monospace;" class=3D"elementToProof"><span st=
yle=3D"line-height: 1.357em;"><code style=3D"font-family: Menlo, Monaco, &q=
uot;Courier New", monospace; display: inline-block;">--fips-limits=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
For libclamav: Enable FIPS-limits for a ClamAV engine like this:</div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 1px; border-sty=
le: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D"p=
resentation" class=3D"elementToProof"><div style=3D"font-family: Menlo, Mon=
aco, "Courier New", monospace;" class=3D"elementToProof"><span st=
yle=3D"line-height: 1.357em;"><code style=3D"font-family: Menlo, Monaco, &q=
uot;Courier New", monospace; display: inline-block;">cl_engine_set_num=
(engine, CL_ENGINE_FIPS_LIMITS, 1);=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
ClamAV will also attempt to detect if FIPS-mode is enabled. If so, it will =
automatically enable the FIPS-limits feature.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
This change mitigates safety concerns over the use of MD5 and SHA1 algorith=
ms to trust files and is required to enable ClamAV to operate legitimately =
in FIPS-mode enabled environments.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Note: ClamAV may still calculate MD5 or SHA1 hashes as needed for detection=
purposes or for informational purposes in FIPS-enabled environments and wh=
en the FIPS-limits option is enabled.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWA1b00fb0b-3e76-2237-7=
a86-362a4ecec347" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Upgraded the clean-file scan cache to use SHA2-256 (prior versions use MD5)=
. The clean-file cache algorithm is not configurable.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
This change resolves safety concerns over the use of MD5 to trust files and=
is required to enable ClamAV to operate legitimately in FIPS-mode enabled =
environments.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWA879b0983-013b-9662-7=
773-f8363aac325b" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request #1</a></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1560" class=3D"OWAAutoLink" id=3D"OWAd9c4337d-eea6-5b27-6=
f9d-7ce3e60f88e5" href=3D"https://github.com/Cisco-Talos/clamav/pull/1560">=
GitHub pull request #2</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
ClamD: Added an option to disable select administrative commands including =
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;">
<code style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;">SHUTDOWN</code></span>,
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">RELOAD</code></span>,
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">STATS</code></span> and
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">VERSION</code></span>.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
The new <span style=3D"font-family: Menlo, Monaco, "Courier New",=
monospace;"><code style=3D"font-family: Menlo, Monaco, "Courier New&q=
uot;, monospace;">clamd.conf</code></span> options are:</div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 1px; border-sty=
le: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D"p=
resentation" class=3D"elementToProof"><div style=3D"font-family: Menlo, Mon=
aco, "Courier New", monospace;" class=3D"elementToProof"><span st=
yle=3D"line-height: 1.357em;"><code style=3D"font-family: Menlo, Monaco, &q=
uot;Courier New", monospace; display: inline-block;">EnableShutdownCom=
mand yes=0A=
EnableReloadCommand yes=0A=
EnableStatsCommand yes=0A=
EnableVersionCommand yes=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
This change courtesy of GitHub user ChaoticByte.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1502" class=3D"OWAAutoLink" id=3D"OWA642fbfd8-6c0d-83df-2=
2ea-ad5034b04937" href=3D"https://github.com/Cisco-Talos/clamav/pull/1502">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
libclamav: Added extended hashing functions with a "flags" parame=
ter that allows the caller to choose if they want to bypass FIPS hash algor=
ithm limits:</div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 1px; border-sty=
le: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D"p=
resentation" class=3D"elementToProof"><div style=3D"font-family: Menlo, Mon=
aco, "Courier New", monospace;" class=3D"elementToProof"><span st=
yle=3D"line-height: 1.357em;"><code style=3D"font-family: Menlo, Monaco, &q=
uot;Courier New", monospace; display: inline-block;">cl_error_t cl_has=
h_data_ex(=0A=
const char *alg,=0A=
const uint8_t *data,=0A=
size_t data_len,=0A=
uint8_t **hash,=0A=
size_t *hash_len,=0A=
uint32_t flags);=0A=
=0A=
cl_error_t cl_hash_init_ex(=0A=
const char *alg,=0A=
uint32_t flags,=0A=
cl_hash_ctx_t **ctx_out);=0A=
=0A=
cl_error_t cl_update_hash_ex(=0A=
cl_hash_ctx_t *ctx,=0A=
const uint8_t *data,=0A=
size_t length);=0A=
=0A=
cl_error_t cl_finish_hash_ex(=0A=
cl_hash_ctx_t *ctx,=0A=
uint8_t **hash,=0A=
size_t *hash_len,=0A=
uint32_t flags);=0A=
=0A=
void cl_hash_destroy(void *ctx);=0A=
=0A=
cl_error_t cl_hash_file_fd_ex(=0A=
const char *alg,=0A=
int fd,=0A=
size_t offset,=0A=
size_t length,=0A=
uint8_t **hash,=0A=
size_t *hash_len,=0A=
uint32_t flags);=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWAcfecbf4b-d7a1-d49d-7=
ae6-a433f9172984" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
ClamScan: Improved the precision of the bytes-scanned and bytes-read counte=
rs. The ClamScan scan summary will now report exact counts in "GiB&quo=
t;, "MiB", "KiB", or "B" as appropriate. Prev=
iously, it always reported "MB".</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWA3cb8032d-f8f3-5b8d-f=
dfd-f5a22b0b44d3" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
ClamScan: Add hash & file-type in/out CLI options:</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
We will not be adding this for ClamDScan, as we do not have a mechanism in =
the ClamD socket API to receive scan options or a way for ClamD to include =
scan metadata in the response.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWA427326d3-b07a-8a79-3=
346-477a9d84dda7" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><ul style=3D"direction: ltr; text-align: left; margin: 0px 0px 0.7em; =
padding-right: 2.5em; padding-left: 2.5em; list-style-position: initial; li=
st-style-type: disc; flex-direction: column; display: flex;" data-line=3D"2=
05">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; align-self: start; text-indent: 0px; line-height: 1.25; margin: 0=
px 0px 0.25em;">
<span role=3D"presentation" style=3D"font-family: Menlo, Monaco, "Cour=
ier New", monospace;"><code style=3D"font-family: Menlo, Monaco, "=
;Courier New", monospace;">--hash-hint</code></span>: The file hash so=
that libclamav does not need to calculate it. The type of
hash must match the <span role=3D"presentation" style=3D"font-family: Menl=
o, Monaco, "Courier New", monospace;">
<code style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;">--hash-alg</code></span>.</li><li style=3D"font-family: Aptos, Aptos_E=
mbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0); direction: ltr; align-self: start; text-indent=
: 0px; line-height: 1.25; margin: 0px 0px 0.25em;">
<span role=3D"presentation" style=3D"font-family: Menlo, Monaco, "Cour=
ier New", monospace;"><code style=3D"font-family: Menlo, Monaco, "=
;Courier New", monospace;">--log-hash</code></span>: Print the file ha=
sh after each file scanned. The type of hash printed will
match the <span role=3D"presentation" style=3D"font-family: Menlo, Monaco,=
"Courier New", monospace;">
<code style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;">--hash-alg</code></span>.</li><li style=3D"font-family: Aptos, Aptos_E=
mbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0); direction: ltr; align-self: start; text-indent=
: 0px; line-height: 1.25; margin: 0px 0px 0.25em;">
<span role=3D"presentation" style=3D"font-family: Menlo, Monaco, "Cour=
ier New", monospace;"><code style=3D"font-family: Menlo, Monaco, "=
;Courier New", monospace;">--hash-alg</code></span>: The hashing algor=
ithm used for either
<span role=3D"presentation" style=3D"font-family: Menlo, Monaco, "Cour=
ier New", monospace;">
<code style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;">--hash-hint</code></span> or
<span role=3D"presentation" style=3D"font-family: Menlo, Monaco, "Cour=
ier New", monospace;">
<code style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;">--log-hash</code></span>. Supported algorithms are "md5", &q=
uot;sha1", "sha2-256". If not specified, the default is &quo=
t;sha2-256".</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, =
Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color=
: rgb(0, 0, 0); direction: ltr; align-self: start; text-indent: 0px; line-h=
eight: 1.25; margin: 0px 0px 0.25em;">
<span role=3D"presentation" style=3D"font-family: Menlo, Monaco, "Cour=
ier New", monospace;"><code style=3D"font-family: Menlo, Monaco, "=
;Courier New", monospace;">--file-type-hint</code></span>: The file ty=
pe hint so that libclamav can optimize scanning (e.g., "pe",
"elf", "zip", etc.). You may also use ClamAV type name=
s such as "CL_TYPE_PE". ClamAV will ignore the hint if it is not =
familiar with the specified type. See also:
<span role=3D"presentation" style=3D"color: rgb(0, 95, 184);"><a style=3D"c=
olor: rgb(0, 95, 184);" data-href=3D"https://docs.clamav.net/appendix/FileT=
ypes.html#file-types" class=3D"OWAAutoLink" id=3D"OWA9b77a859-4cb1-e3d9-723=
1-392edc346318" href=3D"https://docs.clamav.net/appendix/FileTypes.html#fil=
e-types">https://docs.clamav.net/appendix/FileTypes.html#file-types</a></sp=
an></li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontSe=
rvice, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0)=
; direction: ltr; align-self: start; text-indent: 0px; line-height: 1.25; m=
argin: 0px 0px 0.25em;">
<span role=3D"presentation" style=3D"font-family: Menlo, Monaco, "Cour=
ier New", monospace;"><code style=3D"font-family: Menlo, Monaco, "=
;Courier New", monospace;">--log-file-type</code></span>: Print the fi=
le type after each file scanned.</li></ul>
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
libclamav: Added new scan functions that provide additional functionality:<=
/div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 1px; border-sty=
le: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D"p=
resentation" class=3D"elementToProof"><div style=3D"font-family: Menlo, Mon=
aco, "Courier New", monospace;" class=3D"elementToProof"><span st=
yle=3D"line-height: 1.357em;"><code style=3D"font-family: Menlo, Monaco, &q=
uot;Courier New", monospace; display: inline-block;">cl_error_t cl_sca=
nfile_ex(=0A=
const char *filename,=0A=
cl_verdict_t *verdict_out,=0A=
const char **last_alert_out,=0A=
uint64_t *scanned_out,=0A=
const struct cl_engine *engine,=0A=
struct cl_scan_options *scanoptions,=0A=
void *context,=0A=
const char *hash_hint,=0A=
char **hash_out,=0A=
const char *hash_alg,=0A=
const char *file_type_hint,=0A=
char **file_type_out);=0A=
=0A=
cl_error_t cl_scandesc_ex(=0A=
int desc,=0A=
const char *filename,=0A=
cl_verdict_t *verdict_out,=0A=
const char **last_alert_out,=0A=
uint64_t *scanned_out,=0A=
const struct cl_engine *engine,=0A=
struct cl_scan_options *scanoptions,=0A=
void *context,=0A=
const char *hash_hint,=0A=
char **hash_out,=0A=
const char *hash_alg,=0A=
const char *file_type_hint,=0A=
char **file_type_out);=0A=
=0A=
cl_error_t cl_scanmap_ex(=0A=
cl_fmap_t *map,=0A=
const char *filename,=0A=
cl_verdict_t *verdict_out,=0A=
const char **last_alert_out,=0A=
uint64_t *scanned_out,=0A=
const struct cl_engine *engine,=0A=
struct cl_scan_options *scanoptions,=0A=
void *context,=0A=
const char *hash_hint,=0A=
char **hash_out,=0A=
const char *hash_alg,=0A=
const char *file_type_hint,=0A=
char **file_type_out);=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
The older <span style=3D"font-family: Menlo, Monaco, "Courier New"=
;, monospace;"><code style=3D"font-family: Menlo, Monaco, "Courier New=
", monospace;">cl_scan*()</code></span> functions are now depreca=
ted and may be removed in a future release. See
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">clamav.h</code></span> for more details.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWAbdd08ebd-e6b5-9eb8-9=
26f-72d188273cf5" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
libclamav: Added a new engine option to toggle temp directory recursion.</d=
iv>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Temp directory recursion is the idea that each object scanned in ClamAV's r=
ecursive extract/scan process will get a new temp subdirectory, mimicking t=
he nesting structure of the file.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Temp directory recursion was introduced in ClamAV 0.103 and is enabled when=
ever <span style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">
<code style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;">--leave-temps</code></span> /
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">LeaveTemporaryFiles</code></span> is enabled.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
In ClamAV 1.5, an application linking to libclamav can separately enable te=
mp directory recursion if they wish. For ClamScan and ClamD, it will remain=
tied to
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">--leave-temps</code></span> /
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">LeaveTemporaryFiles</code></span> options.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
The new temp directory recursion option can be enabled with:</div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 1px; border-sty=
le: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D"p=
resentation" class=3D"elementToProof"><div style=3D"font-family: Menlo, Mon=
aco, "Courier New", monospace;" class=3D"elementToProof"><span st=
yle=3D"line-height: 1.357em;"><code style=3D"font-family: Menlo, Monaco, &q=
uot;Courier New", monospace; display: inline-block;">cl_engine_set_num=
(engine, CL_ENGINE_TMPDIR_RECURSION, 1);=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWA1fa43fc3-2d85-00eb-e=
38e-a5b5d77d909d" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
libclamav: Added a class of scan callback functions that can be added with =
the following API function:</div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 1px; border-sty=
le: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D"p=
resentation" class=3D"elementToProof"><div style=3D"font-family: Menlo, Mon=
aco, "Courier New", monospace;" class=3D"elementToProof"><span st=
yle=3D"line-height: 1.357em;"><code style=3D"font-family: Menlo, Monaco, &q=
uot;Courier New", monospace; display: inline-block;">void cl_engine_se=
t_scan_callback(struct cl_engine *engine, clcb_scan callback, cl_scan_callb=
ack_t location);=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
The scan callback location may be configured using the following five value=
s:</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Each callback may alter scan behavior using the following return codes:</di=
v>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Each callback is given a pointer to the current scan layer from which they =
can get previous layers, can get the layer's fmap, and then various attribu=
tes of the layer and of the fmap. To make this possible, there are new APIs=
to query scan-layer details and
fmap details:</div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 1px; border-sty=
le: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D"p=
resentation" class=3D"elementToProof"><div style=3D"font-family: Menlo, Mon=
aco, "Courier New", monospace;" class=3D"elementToProof"><span st=
yle=3D"line-height: 1.357em;"><code style=3D"font-family: Menlo, Monaco, &q=
uot;Courier New", monospace; display: inline-block;"> cl_error_t=
cl_fmap_set_name(cl_fmap_t *map, const char *name);=0A=
cl_error_t cl_fmap_get_name(cl_fmap_t *map, const char **name_out);=
=0A=
cl_error_t cl_fmap_set_path(cl_fmap_t *map, const char *path);=0A=
cl_error_t cl_fmap_get_path(cl_fmap_t *map, const char **path_out, s=
ize_t *offset_out, size_t *len_out);=0A=
cl_error_t cl_fmap_get_fd(const cl_fmap_t *map, int *fd_out, size_t =
*offset_out, size_t *len_out);=0A=
cl_error_t cl_fmap_get_size(const cl_fmap_t *map, size_t *size_out);=
=0A=
cl_error_t cl_fmap_set_hash(const cl_fmap_t *map, const char *hash_a=
lg, char hash);=0A=
cl_error_t cl_fmap_have_hash(const cl_fmap_t *map, const char *hash_=
alg, bool *have_hash_out);=0A=
cl_error_t cl_fmap_will_need_hash_later(const cl_fmap_t *map, const =
char *hash_alg);=0A=
cl_error_t cl_fmap_get_hash(const cl_fmap_t *map, const char *hash_a=
lg, char **hash_out);=0A=
cl_error_t cl_fmap_get_data(const cl_fmap_t *map, size_t offset, siz=
e_t len, const uint8_t **data_out, size_t *data_len_out);=0A=
cl_error_t cl_scan_layer_get_fmap(cl_scan_layer_t *layer, cl_fmap_t =
**fmap_out);=0A=
cl_error_t cl_scan_layer_get_parent_layer(cl_scan_layer_t *layer, cl=
_scan_layer_t **parent_layer_out);=0A=
cl_error_t cl_scan_layer_get_type(cl_scan_layer_t *layer, const char=
**type_out);=0A=
cl_error_t cl_scan_layer_get_recursion_level(cl_scan_layer_t *layer,=
uint32_t *recursion_level_out);=0A=
cl_error_t cl_scan_layer_get_object_id(cl_scan_layer_t *layer, uint6=
4_t *object_id_out);=0A=
cl_error_t cl_scan_layer_get_last_alert(cl_scan_layer_t *layer, cons=
t char **alert_name_out);=0A=
cl_error_t cl_scan_layer_get_attributes(cl_scan_layer_t *layer, uint=
32_t *attributes_out);=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
This deprecates, but does not immediately remove, the existing scan callbac=
ks:</div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 1px; border-sty=
le: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D"p=
resentation" class=3D"elementToProof"><div style=3D"font-family: Menlo, Mon=
aco, "Courier New", monospace;" class=3D"elementToProof"><span st=
yle=3D"line-height: 1.357em;"><code style=3D"font-family: Menlo, Monaco, &q=
uot;Courier New", monospace; display: inline-block;"> void cl_en=
gine_set_clcb_pre_cache(struct cl_engine *engine, clcb_pre_cache callback);=
=0A=
void cl_engine_set_clcb_file_inspection(struct cl_engine *engine, cl=
cb_file_inspection callback);=0A=
void cl_engine_set_clcb_pre_scan(struct cl_engine *engine, clcb_pre_=
scan callback);=0A=
void cl_engine_set_clcb_post_scan(struct cl_engine *engine, clcb_pos=
t_scan callback);=0A=
void cl_engine_set_clcb_virus_found(struct cl_engine *engine, clcb_v=
irus_found callback);=0A=
void cl_engine_set_clcb_hash(struct cl_engine *engine, clcb_hash cal=
lback);=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
There is an interactive test program to demonstrate the new callbacks. See:=
<span style=3D"font-family: Menlo, Monaco, "Courier New", monosp=
ace;">
<code style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;">examples/ex_scan_callbacks.c</code></span></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWAd153ebfd-25a3-a31c-e=
e2f-43db26e75b9e" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><ul style=3D"direction: ltr; text-align: left; margin: 0px 0px 0.7em; =
padding-right: 2.5em; padding-left: 2.5em; list-style-position: initial; li=
st-style-type: disc; flex-direction: column; display: flex;" data-line=3D"3=
05">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; align-self: start; text-indent: 0px; line-height: 1.25; margin: 0=
px 0px 0.25em;">
<span role=3D"presentation" style=3D"font-family: Menlo, Monaco, "Cour=
ier New", monospace;"><code style=3D"font-family: Menlo, Monaco, "=
;Courier New", monospace;">CL_SCAN_CALLBACK_PRE_HASH</code></span>: Oc=
curs just after basic file-type detection and before any hashes
have been calculated either for the cache or the gen-json metadata.</li><l=
i style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Cal=
ibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); directio=
n: ltr; align-self: start; text-indent: 0px; line-height: 1.25; margin: 0px=
0px 0.25em;">
<span role=3D"presentation" style=3D"font-family: Menlo, Monaco, "Cour=
ier New", monospace;"><code style=3D"font-family: Menlo, Monaco, "=
;Courier New", monospace;">CL_SCAN_CALLBACK_PRE_SCAN</code></span>: Oc=
curs before parser modules run and before pattern matching.</li><li style=
=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, H=
elvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direction: ltr;=
align-self: start; text-indent: 0px; line-height: 1.25; margin: 0px 0px 0.=
25em;">
<span role=3D"presentation" style=3D"font-family: Menlo, Monaco, "Cour=
ier New", monospace;"><code style=3D"font-family: Menlo, Monaco, "=
;Courier New", monospace;">CL_SCAN_CALLBACK_POST_SCAN</code></span>: O=
ccurs after pattern matching and after running parser modules.
A.k.a. the scan is complete for this layer.</li><li style=3D"font-family: =
Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-se=
rif; font-size: 12pt; color: rgb(0, 0, 0); direction: ltr; align-self: star=
t; text-indent: 0px; line-height: 1.25; margin: 0px 0px 0.25em;">
<span role=3D"presentation" style=3D"font-family: Menlo, Monaco, "Cour=
ier New", monospace;"><code style=3D"font-family: Menlo, Monaco, "=
;Courier New", monospace;">CL_SCAN_CALLBACK_ALERT</code></span>: Occur=
s each time an alert (detection) would be triggered during
a scan.</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSF=
ontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, =
0, 0); direction: ltr; align-self: start; text-indent: 0px; line-height: 1.=
25; margin: 0px 0px 0.25em;">
<span role=3D"presentation" style=3D"font-family: Menlo, Monaco, "Cour=
ier New", monospace;"><code style=3D"font-family: Menlo, Monaco, "=
;Courier New", monospace;">CL_SCAN_CALLBACK_FILE_TYPE</code></span>: O=
ccurs each time the file type determination is refined. This
may happen more than once per layer.</li><li style=3D"font-family: Aptos, =
Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; fo=
nt-size: 12pt; color: rgb(0, 0, 0); direction: ltr; text-indent: 0px; margi=
n: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">CL_BREAK</code></span>: Scan aborted by callback. The rest of the=
scan is skipped. This does not mark the file as clean or
infected, it just skips the rest of the scan.</div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">CL_SUCCESS</code></span> /
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">CL_CLEAN</code></span>: File scan will continue.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
For <span style=3D"font-family: Menlo, Monaco, "Courier New", mon=
ospace;"><code style=3D"font-family: Menlo, Monaco, "Courier New"=
, monospace;">CL_SCAN_CALLBACK_ALERT</code></span>: This means you want to =
ignore this specific alert and keep scanning.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
This is different than <span style=3D"font-family: Menlo, Monaco, "Cou=
rier New", monospace;">
<code style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;">CL_VERIFIED</code></span> because it does not affect prior or fut=
ure alerts. Return
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">CL_VERIFIED</code></span> instead if you want to remove prio=
r alerts for this layer and skip the rest of the scan for this
layer.</div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">CL_VIRUS</code></span>: This means you do not trust the file. A n=
ew alert will be added.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
For <span style=3D"font-family: Menlo, Monaco, "Courier New", mon=
ospace;"><code style=3D"font-family: Menlo, Monaco, "Courier New"=
, monospace;">CL_SCAN_CALLBACK_ALERT</code></span>: This means you agree wi=
th the alert and no extra alert is needed.</div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">CL_VERIFIED</code></span>: Layer explicitly trusted by the callba=
ck and previous alerts removed for THIS layer. You might
want to do this if you trust the hash or verified a digital signature. The=
rest of the scan will be skipped for THIS layer. For contained files, this=
does NOT mean that the parent or adjacent layers are trusted.</div>
</li></ul>
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Signature names that start with "Weak." will no longer alert. Ins=
tead, they will be tracked internally and can be found in scan metadata JSO=
N. This is a step towards enabling alerting signatures to depend on prior W=
eak indicator matches in the current layer
or in child layers.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWA7ffbba74-44bf-ed6f-6=
455-6090438077e7" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
For the "Generate Metadata JSON" feature:</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWAe23a1286-bee1-b16c-a=
ab9-6006df577f91" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><ul style=3D"direction: ltr; text-align: left; margin: 0px 0px 0.7em; =
padding-right: 2.5em; padding-left: 2.5em; list-style-position: initial; li=
st-style-type: disc;" data-line=3D"392">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
The "Viruses" array of alert names has been replaced by two new a=
rrays that include additional details beyond just signature name:</div>
</li><ul style=3D"direction: ltr; text-align: left; margin: 0px 0px 0.7em; =
padding-right: 2.5em; padding-left: 2.5em; list-style-position: initial; li=
st-style-type: disc; flex-direction: column; display: flex;" data-line=3D"3=
94">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; align-self: start; text-indent: 0px; line-height: 1.25; margin: 0=
px 0px 0.25em;">
"Indicators" records three types of indicators:</li><ul style=3D"=
direction: ltr; text-align: left; margin: 0px; padding-right: 2.5em; paddin=
g-left: 2.5em; list-style-position: initial; list-style-type: disc; flex-di=
rection: column; display: flex;" data-line=3D"395">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; align-self: start; text-indent: 0px; line-height: 1.25; margin: 0=
px 0px 0.25em;">
<b>Strong</b> indicators are for traditional alerting signature matche=
s and will halt the scan, except in all-match mode.</li><li style=3D"font-f=
amily: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, =
sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direction: ltr; align-sel=
f: start; text-indent: 0px; line-height: 1.25; margin: 0px 0px 0.25em;">
<b>Potentially Unwanted</b> indicators will only cause an alert at the=
end of the scan unless a Strong indicator is found. They are treated the s=
ame as Strong indicators in all-match mode.</li><li style=3D"font-family: A=
ptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-ser=
if; font-size: 12pt; color: rgb(0, 0, 0); direction: ltr; align-self: start=
; text-indent: 0px; line-height: 1.25; margin: 0px 0px 0.25em;">
<b>Weak</b> indicators do not alert and will be leveraged in a future =
version as a condition for logical signature matches.</li></ul>
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; align-self: start; text-indent: 0px; line-height: 1.25; margin: 0=
px 0px 0.25em;">
"Alerts" records only alerting indicators. Events that trust a fi=
le, such as false positive signatures, will remove affected indicators, and=
mark them as "Ignored" in the "Indicators" array.</li>=
</ul>
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Add new option to calculate and record additional hash types when the "=
;generate metadata JSON" feature is enabled:</div>
</li><ul style=3D"direction: ltr; text-align: left; margin: 0px 0px 0.7em; =
padding-right: 2.5em; padding-left: 2.5em; list-style-position: initial; li=
st-style-type: disc; flex-direction: column; display: flex;" data-line=3D"4=
08">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; align-self: start; text-indent: 0px; line-height: 1.25; margin: 0=
px 0px 0.25em;">
libclamav option: <span role=3D"presentation" style=3D"font-family: Menlo, =
Monaco, "Courier New", monospace;">
<code style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;">CL_SCAN_GENERAL_STORE_EXTRA_HASHES</code></span></li><li style=3D"font=
-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica=
, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direction: ltr; align-s=
elf: start; text-indent: 0px; line-height: 1.25; margin: 0px 0px 0.25em;">
ClamScan option: <span role=3D"presentation" style=3D"font-family: Menlo, M=
onaco, "Courier New", monospace;">
<code style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;">--json-store-extra-hashes</code></span> (default off)</li><li sty=
le=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri,=
Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direction: lt=
r; align-self: start; text-indent: 0px; line-height: 1.25; margin: 0px 0px =
0.25em;">
<span role=3D"presentation" style=3D"font-family: Menlo, Monaco, "Cour=
ier New", monospace;"><code style=3D"font-family: Menlo, Monaco, "=
;Courier New", monospace;">clamd.conf</code></span> option:
<span role=3D"presentation" style=3D"font-family: Menlo, Monaco, "Cour=
ier New", monospace;">
<code style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;">JsonStoreExtraHashes</code></span> (default 'no')</li></ul>
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
The file hash is now stored as "sha2-256" instead of "FileMD=
5". If you enable the "extra hashes" option, then it will al=
so record "md5" and "sha1".</div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Each object scanned now has a unique "Object ID".</div>
</li></ul>
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Sigtool: Renamed the sigtool option <span style=3D"font-family: Menlo, Mona=
co, "Courier New", monospace;">
<code style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;">--sha256</code></span> to
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">--sha2-256</code></span>. The original option is still functional=
but is deprecated.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWA4f1b1842-3256-1e35-2=
837-40a45bcb5127" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li></ul>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin: 24px 0px 16px; font-family: Aptos, Aptos_EmbeddedFont, Ap=
tos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: =
rgb(0, 0, 0);" class=3D"elementToProof" id=3D"other-improvements">
<b>Other improvements</b></div>
<ul style=3D"direction: ltr; text-align: left; margin: 0px 0px 0.7em; paddi=
ng-right: 2.5em; padding-left: 2.5em; list-style-position: initial; list-st=
yle-type: disc;" data-line=3D"426">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Set a limit on the max-recursion config option. Users will no longer be abl=
e to set max-recursion higher than 100. This change prevents errors on star=
t up or crashes if encountering a file with that many layers of recursion.<=
/div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1264" class=3D"OWAAutoLink" id=3D"OWA5b8140f2-20af-12f8-1=
bb8-e8902b03539e" href=3D"https://github.com/Cisco-Talos/clamav/pull/1264">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Build system: CMake improvements to support compiling for the AIX platform.=
This change is courtesy of GitHub user KamathForAIX.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1387" class=3D"OWAAutoLink" id=3D"OWAa06ac793-c596-1d1b-5=
605-da29389103b0" href=3D"https://github.com/Cisco-Talos/clamav/pull/1387">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Improve support for extracting malformed zip archives. This change is court=
esy of Frederick Sell.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1460" class=3D"OWAAutoLink" id=3D"OWA0a6733e6-de05-db58-3=
5aa-c100eea1bd19" href=3D"https://github.com/Cisco-Talos/clamav/pull/1460">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Windows: Code quality improvement for the ClamScan and ClamDScan <span styl=
e=3D"font-family: Menlo, Monaco, "Courier New", monospace;">
<code style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;">--move</code></span> and
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">--remove</code></span> options. This change is courtesy of M=
axim Suhanov.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1470" class=3D"OWAAutoLink" id=3D"OWA34cf94e3-da54-2bc8-d=
da7-f77eb2b90877" href=3D"https://github.com/Cisco-Talos/clamav/pull/1470">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Added file type recognition for an initial set of AI model file types.</div=
>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
The file type is accessible to applications using libclamav via the scan ca=
llback functions and as an optional output parameter to the scan functions:
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">cl_scanfile_ex()</code></span>,
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">cl_scanmap_ex()</code></span>, and
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">cl_scandesc_ex()</code></span>.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
When scanning these files, type will now show "CL_TYPE_AI_MODEL" =
instead of "CL_TYPE_BINARY_DATA".</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1476" class=3D"OWAAutoLink" id=3D"OWAa53143f8-2a82-b061-3=
2da-d84337079208" href=3D"https://github.com/Cisco-Talos/clamav/pull/1476">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Added support for inline comments in ClamAV configuration files. This chang=
e is courtesy of GitHub user userwiths.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1308" class=3D"OWAAutoLink" id=3D"OWA3a45a53b-9628-2d90-7=
21c-8ac2680dd3f9" href=3D"https://github.com/Cisco-Talos/clamav/pull/1308">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Disabled the MyDoom hardcoded/heuristic detection because of false positive=
s.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1495" class=3D"OWAAutoLink" id=3D"OWAff814d53-ed08-c431-4=
671-966f7f82901c" href=3D"https://github.com/Cisco-Talos/clamav/pull/1495">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Sigtool: Added support for creating <span style=3D"font-family: Menlo, Mona=
co, "Courier New", monospace;">
<code style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;">.cdiff</code></span> and
<span style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;"><code style=3D"font-family: Menlo, Monaco, "Courier New", mo=
nospace;">.script</code></span> patch files for CVDs that have undersc=
ores in the CVD name. Also improved support for relative paths
with the <span style=3D"font-family: Menlo, Monaco, "Courier New"=
;, monospace;"><code style=3D"font-family: Menlo, Monaco, "Courier New=
", monospace;">--diff</code></span> command.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1541" class=3D"OWAAutoLink" id=3D"OWAe35666d8-b4a1-4f19-9=
b24-338ca31f2596" href=3D"https://github.com/Cisco-Talos/clamav/pull/1541">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Windows: Improved support for file names with UTF-8 characters not found in=
the ANSI or OEM code pages when printing scan results or showing activity =
in the ClamDTOP monitoring utility. Fixed a bug with opening files with suc=
h names with the Sigtool utility.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1461" class=3D"OWAAutoLink" id=3D"OWA76e50dd7-29f0-7f47-9=
6fe-c12acde2b33f" href=3D"https://github.com/Cisco-Talos/clamav/pull/1461">=
GitHub pull request #1</a></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1537" class=3D"OWAAutoLink" id=3D"OWA29c0d767-7dba-a57f-d=
e92-d4f1340704da" href=3D"https://github.com/Cisco-Talos/clamav/pull/1537">=
GitHub pull request #2</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Improved the code quality of the ZIP module. Added inline documentation.</d=
iv>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1548" class=3D"OWAAutoLink" id=3D"OWA5985e3d3-b0c8-bfda-7=
626-6187fe972a72" href=3D"https://github.com/Cisco-Talos/clamav/pull/1548">=
GitHub pull request #1</a></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1552" class=3D"OWAAutoLink" id=3D"OWAce464833-a80d-10ba-5=
a10-a51382c290d3" href=3D"https://github.com/Cisco-Talos/clamav/pull/1552">=
GitHub pull request #2</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Always run scan callbacks for embedded files. Embedded files are found with=
in other files through signature matches instead of by parsing. They will n=
ow be processed the same way and then they can trigger application callback=
s (e.g., "pre-scan", "post-scan",
etc.).</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
A consequence of this change is that each embedded file will be pattern- ma=
tched just like any other extracted file. To minimize excessive pattern mat=
ching, file header validation checks were added for ZIP, ARJ, and CAB. Also=
fixed a bug with embedded PE file
scanning to reduce unnecessary matching.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
This change will impact scans with both the "leave-temps" feature=
and the "force-to-disk" feature enabled, resulting in additional=
temporary files.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWAd504a5c4-023b-bb49-9=
5c2-25ca2e05f35e" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request #1</a></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1571" class=3D"OWAAutoLink" id=3D"OWA02cb4fce-6cc7-7754-9=
ebe-8e55adafceaa" href=3D"https://github.com/Cisco-Talos/clamav/pull/1571">=
GitHub pull request #2</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Added DevContainer templates to the ClamAV Git repository in order to make =
it easier to set up AlmaLinux or Debian development environments.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1462" class=3D"OWAAutoLink" id=3D"OWA5ea907a0-50d1-f6c8-1=
5fc-93cd7f3fe3e0" href=3D"https://github.com/Cisco-Talos/clamav/pull/1462">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Removed the "Heuristics.XZ.DicSizeLimit" alert because of potenti=
al unintended alerts based on system state.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1573" class=3D"OWAAutoLink" id=3D"OWAd538844e-4871-cfb8-f=
a02-3a1e9ed25da2" href=3D"https://github.com/Cisco-Talos/clamav/pull/1573">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Improved support for compiling on Solaris.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
This fix courtesy of Andrew Watkins.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1569" class=3D"OWAAutoLink" id=3D"OWA2a94f08d-1eba-5e74-d=
7cf-9ae0749806e9" href=3D"https://github.com/Cisco-Talos/clamav/pull/1569">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Improved support for compiling on GNU/Hurd.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
This fix courtesy of Pino Toscano.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1569" class=3D"OWAAutoLink" id=3D"OWA5bca4ee2-3e5f-6799-2=
ee4-ae9064607392" href=3D"https://github.com/Cisco-Talos/clamav/pull/1569">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Improved support for linking with the NCurses library dependency when libti=
nfo is built as a separate library.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1356" class=3D"OWAAutoLink" id=3D"OWA3780edc1-0bf5-cc4f-f=
41e-22eb9ed7d33f" href=3D"https://github.com/Cisco-Talos/clamav/pull/1356">=
GitHub pull request</a></div>
</li></ul>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin: 24px 0px 16px; font-family: Aptos, Aptos_EmbeddedFont, Ap=
tos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: =
rgb(0, 0, 0);" class=3D"elementToProof" id=3D"bug-fixes">
<b>Bug fixes</b></div>
<ul style=3D"direction: ltr; text-align: left; margin: 0px 0px 0.7em; paddi=
ng-right: 2.5em; padding-left: 2.5em; list-style-position: initial; list-st=
yle-type: disc;" data-line=3D"536">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Reduced email multipart message parser complexity.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1347" class=3D"OWAAutoLink" id=3D"OWA0cb34e28-a6c5-9177-b=
142-1d835c763290" href=3D"https://github.com/Cisco-Talos/clamav/pull/1347">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Fixed possible undefined behavior in inflate64 module. The inflate64 module=
is a modified version of the zlib library, taken from version 1.2.3 with s=
ome customization and with some cherry-picked fixes. This adds one addition=
al fix from zlib 1.2.9. Thank you
to TITAN Team for reporting this issue.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1469" class=3D"OWAAutoLink" id=3D"OWA05285ef7-23ad-fe3b-f=
099-2ce010ffee5e" href=3D"https://github.com/Cisco-Talos/clamav/pull/1469">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Fixed a bug in ClamD that broke reporting of memory usage on Linux. The STA=
TS command can be used to monitor ClamD directly or through ClamDTOP. The m=
emory stats feature does not work on all platforms (e.g., Windows).</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1465" class=3D"OWAAutoLink" id=3D"OWAb5f5b103-006c-7603-1=
a44-87c6fd67ca62" href=3D"https://github.com/Cisco-Talos/clamav/pull/1465">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Windows: Fixed a build issue when the same library dependency is found in t=
wo different locations.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1453" class=3D"OWAAutoLink" id=3D"OWAe6ebc665-c2a9-4dcc-a=
253-2e26ec3ce0bd" href=3D"https://github.com/Cisco-Talos/clamav/pull/1453">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Fixed an infinite loop when scanning some email files in debug-mode. This f=
ix is courtesy of Yoann Lecuyer.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1445" class=3D"OWAAutoLink" id=3D"OWA7738bcfd-20f0-8c3e-1=
eb8-fafacab14561" href=3D"https://github.com/Cisco-Talos/clamav/pull/1445">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Fixed a stack buffer overflow bug in the phishing signature load process. T=
his fix is courtesy of GitHub user Shivam7-1.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1486" class=3D"OWAAutoLink" id=3D"OWAfa195768-7ce4-97e9-a=
4d2-b49e63aa1f3b" href=3D"https://github.com/Cisco-Talos/clamav/pull/1486">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Fixed a race condition in the Freshclam feature tests. This fix is courtesy=
of GitHub user rma-x.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1513" class=3D"OWAAutoLink" id=3D"OWA6fed86e5-7d10-b804-c=
abf-06341b0ba087" href=3D"https://github.com/Cisco-Talos/clamav/pull/1513">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Windows: Fixed a 5-byte heap buffer overread in the Windows unit tests. Thi=
s fix is courtesy of GitHub user Sophie0x2E.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1542" class=3D"OWAAutoLink" id=3D"OWA0e5d1161-5b5e-0588-a=
8ff-874a1ec9d59e" href=3D"https://github.com/Cisco-Talos/clamav/pull/1542">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Fix double-extraction of OOXML-based office documents.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWA9819d00b-a44d-20fb-1=
2dc-95bc1c5b8266" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
ClamBC: Fixed crashes on startup.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWA38ae7135-0eb1-6035-2=
5e5-d11db1dc700a" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Fixed an assortment of issues found with Coverity static analysis.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1574" class=3D"OWAAutoLink" id=3D"OWAcd3920a6-1f06-625c-3=
676-0af7df7f1eff" href=3D"https://github.com/Cisco-Talos/clamav/pull/1574">=
GitHub pull request #1</a></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1582" class=3D"OWAAutoLink" id=3D"OWA6f38c209-c864-ec9e-c=
937-a5e147c3d23e" href=3D"https://github.com/Cisco-Talos/clamav/pull/1582">=
GitHub pull request #2</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Fixed libclamav unit test, ClamD, and ClamDScan Valgrind test failures affe=
cting some platforms.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1554" class=3D"OWAAutoLink" id=3D"OWAba88210c-b762-f751-e=
44a-4b8f8d162721" href=3D"https://github.com/Cisco-Talos/clamav/pull/1554">=
GitHub pull request #1</a></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1570" class=3D"OWAAutoLink" id=3D"OWAc04bf08c-6d63-581c-b=
2d9-b59e805171ff" href=3D"https://github.com/Cisco-Talos/clamav/pull/1570">=
GitHub pull request #2</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Fixed crash in the Sigtool program when using the <span style=3D"font-famil=
y: Menlo, Monaco, "Courier New", monospace;">
<code style=3D"font-family: Menlo, Monaco, "Courier New", monospa=
ce;">--html-normalize</code></span> option.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1556" class=3D"OWAAutoLink" id=3D"OWAd70a9466-6cde-2495-f=
cc3-7bc21b03dba9" href=3D"https://github.com/Cisco-Talos/clamav/pull/1556">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Fixed some potential NULL-pointer dereference issues if memory allocations =
fail.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em;" role=3D"presentation" cla=
ss=3D"elementToProof">
Fix courtesy of GitHub user JiangJias.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin-top: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" r=
ole=3D"presentation" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1581" class=3D"OWAAutoLink" id=3D"OWAf91350bc-77a1-cf10-f=
1d3-7c1770c9a59a" href=3D"https://github.com/Cisco-Talos/clamav/pull/1581">=
GitHub pull request</a></div>
</li></ul>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin: 24px 0px 16px; font-family: Aptos, Aptos_EmbeddedFont, Ap=
tos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: =
rgb(0, 0, 0);" class=3D"elementToProof" id=3D"acknowledgments">
<b>Acknowledgments</b></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin: 0px 0px 16px; font-family: Aptos, Aptos_EmbeddedFont, Apt=
os_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: r=
gb(0, 0, 0);" class=3D"elementToProof">
Special thanks to the following people for code contributions and bug repor=
ts:</div>
<ul style=3D"direction: ltr; text-align: left; margin: 0px 0px 0.7em; paddi=
ng-right: 2.5em; padding-left: 2.5em; list-style-position: initial; list-st=
yle-type: disc; flex-direction: column; display: flex;" data-line=3D"614">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; align-self: start; text-indent: 0px; line-height: 1.25; margin: 0=
px 0px 0.25em;">
Andrew Watkins</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Apt=
os_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: r=
gb(0, 0, 0); direction: ltr; align-self: start; text-indent: 0px; line-heig=
ht: 1.25; margin: 0px 0px 0.25em;">
b1tg</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontS=
ervice, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0=
); direction: ltr; align-self: start; text-indent: 0px; line-height: 1.25; =
margin: 0px 0px 0.25em;">
ChaoticByte</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_=
MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(=
0, 0, 0); direction: ltr; align-self: start; text-indent: 0px; line-height:=
1.25; margin: 0px 0px 0.25em;">
Frederick Sell</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Apt=
os_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: r=
gb(0, 0, 0); direction: ltr; align-self: start; text-indent: 0px; line-heig=
ht: 1.25; margin: 0px 0px 0.25em;">
KamathForAIX</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos=
_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb=
(0, 0, 0); direction: ltr; align-self: start; text-indent: 0px; line-height=
: 1.25; margin: 0px 0px 0.25em;">
Mark Carey at SAP</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, =
Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color=
: rgb(0, 0, 0); direction: ltr; align-self: start; text-indent: 0px; line-h=
eight: 1.25; margin: 0px 0px 0.25em;">
Maxim Suhanov</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Apto=
s_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rg=
b(0, 0, 0); direction: ltr; align-self: start; text-indent: 0px; line-heigh=
t: 1.25; margin: 0px 0px 0.25em;">
Pino Toscano</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos=
_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb=
(0, 0, 0); direction: ltr; align-self: start; text-indent: 0px; line-height=
: 1.25; margin: 0px 0px 0.25em;">
rma-x</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFont=
Service, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, =
0); direction: ltr; align-self: start; text-indent: 0px; line-height: 1.25;=
margin: 0px 0px 0.25em;">
Shivam7-1</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MS=
FontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0,=
0, 0); direction: ltr; align-self: start; text-indent: 0px; line-height: 1=
.25; margin: 0px 0px 0.25em;">
Sophie0x2E</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_M=
SFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0=
, 0, 0); direction: ltr; align-self: start; text-indent: 0px; line-height: =
1.25; margin: 0px 0px 0.25em;">
TITAN Team</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_M=
SFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0=
, 0, 0); direction: ltr; align-self: start; text-indent: 0px; line-height: =
1.25; margin: 0px 0px 0.25em;">
userwiths</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MS=
FontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0,=
0, 0); direction: ltr; align-self: start; text-indent: 0px; line-height: 1=
.25; margin: 0px 0px 0.25em;">
Yoann Lecuyer</li></ul>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
<br>
</div>
<div class=3D"elementToProof" id=3D"Signature">
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
<span style=3D"font-family: Calibri, Arial, Helvetica, sans-serif;"><br>
</span><span style=3D"font-family: Helvetica; font-size: 12px;">Valerie Sny=
der (she/they)</span><span style=3D"font-family: Calibri, Arial, Helvetica,=
sans-serif;"><br>
</span><span style=3D"font-family: Helvetica; font-size: 12px;">ClamAV Deve=
lopment</span><span style=3D"font-family: Calibri, Arial, Helvetica, sans-s=
erif;"><br>
</span><span style=3D"font-family: Helvetica; font-size: 12px;">Talos</span=
><span style=3D"font-family: Calibri, Arial, Helvetica, sans-serif;"><br>
</span><span style=3D"font-family: Helvetica; font-size: 12px;">Cisco Syste=
ms, Inc.</span><span style=3D"font-family: Calibri, Arial, Helvetica, sans-=
serif;"><br>
</span></div>
</div>
</body>
</html>
--_000_CH3PR11MB87501812051B3417B51CBB1EC6E0ACH3PR11MB8750namp_--
--===============8638913628983763905==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
clamav-announce mailing list
[email protected]
https://lists.clamav.net/mailman/listinfo/clamav-announce
http://www.clamav.net/contact.html#ml
--===============8638913628983763905==--