ClamAV 1.5.1 patch version published
"Val Snyder \(micasnyd\) via clamav-announce" <[email protected]> Thu, 16 Oct 2025 15:23:49 +0000
| Newsgroups | gmane.comp.security.virus.clamav.announce |
|---|---|
| Message-ID | <CH3PR11MB875055C899DD97A8E624C705C6E9A__19327.0978795894$1760628478$gmane$org@CH3PR11MB8750.namprd11.prod.outlook.com> |
--===============4278828440697883903==
Content-Language: en-US
Content-Type: multipart/alternative;
boundary="_000_CH3PR11MB875055C899DD97A8E624C705C6E9ACH3PR11MB8750namp_"
--_000_CH3PR11MB875055C899DD97A8E624C705C6E9ACH3PR11MB8750namp_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
Read this online at: https://blog.clamav.net/2025/10/clamav-151-patch-versi=
on-published.html
Today, we are publishing ClamAV 1.5.1.
This version has been released shortly after ClamAV 1.5.0 in order to addre=
ss several significant issues that were identified following its publicatio=
n.
The release files for the patch versions are available for download on the =
ClamAV downloads page<https://www.clamav.net/downloads>, on the GitHub Rele=
ase page<https://github.com/Cisco-Talos/clamav/releases>, and through Docke=
r Hub<https://hub.docker.com/r/clamav/clamav/>. The images on Docker Hub ma=
y not be immediately available on release day.
ClamAV 1.5.1 is a patch release with the following fixes:
*
Fixed a significant performance issue when scanning some PE files
*
Fixed an issue recording file entries from a ZIP archive central directory =
which resulted in "Heuristics.Limits.Exceeded.MaxFiles" alerts when using t=
he ClamScan --alert-exceeds-max command line option or ClamD AlertExceedsMa=
x config file option
*
Improved performance when scanning TNEF email attachments
*
Fixed an issue with recording metadata for OOXML office documents
*
Fixed an issue with signature matches for VBA in OLE2 office documents
*
Loosened overly restrictive rules for embedded file identification and incr=
eased the limit for finding PE files embedded in other PE files
*
Fixed an issue with extracting some RAR archives embedded in other files
*
Fixed an issue with calculating fuzzy hashes affecting some images by updat=
ing the version for several Rust library dependencies
* This release does not require a newer version of the Rust compiler=
toolchain than what was required for ClamAV 1.5.0
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1606>
Respectfully,
Val
Valerie Snyder (she/they)
ClamAV Development
Talos
Cisco Systems, Inc.
--_000_CH3PR11MB875055C899DD97A8E624C705C6E9ACH3PR11MB8750namp_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<style type=3D"text/css" style=3D"display:none;"> P {margin-top:0;margin-bo=
ttom:0;} </style>
</head>
<body dir=3D"ltr">
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; color: rgb(0, 0, 0=
);">
<span style=3D"font-size: 10pt;">Read this online at: <a class=3D"OWAAutoLi=
nk" href=3D"https://blog.clamav.net/2025/10/clamav-151-patch-version-publis=
hed.html" id=3D"LPlnk702145">
https://blog.clamav.net/2025/10/clamav-151-patch-version-published.html</a>=
</span></div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; color: rgb(0, 0, 0=
);">
<span style=3D"font-size: 10pt;"></span><span style=3D"font-size: 12pt;"><b=
r>
</span></div>
<div id=3D"post-body-49704958551827105" class=3D"elementToProof">
<div class=3D"elementToProof" style=3D"text-align: left; text-indent: 0px; =
line-height: 1.4; margin-top: 1em; margin-bottom: 1em; font-family: Aptos, =
Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; fo=
nt-size: 12pt; color: rgb(0, 0, 0);">
Today, we are publishing ClamAV 1.5.1.</div>
<div class=3D"elementToProof" style=3D"text-align: left; text-indent: 0px; =
line-height: 1.4; margin-top: 1em; margin-bottom: 1em; font-family: Aptos, =
Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; fo=
nt-size: 12pt; color: rgb(0, 0, 0);">
This version has been released shortly after ClamAV 1.5.0 in order to addre=
ss several significant issues that were identified following its publicatio=
n.</div>
<div class=3D"elementToProof" style=3D"text-align: left; text-indent: 0px; =
line-height: 1.4; margin-top: 1em; margin-bottom: 1em; font-family: Aptos, =
Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; fo=
nt-size: 12pt;">
<span style=3D"color: rgb(0, 0, 0);">The release files for the patch versio=
ns are available for download on the
</span><span style=3D"color: rgb(239, 62, 66);"><a href=3D"https://www.clam=
av.net/downloads" target=3D"_blank" id=3D"OWAb2d68317-284a-da4d-b36f-ef4b19=
8a75db" class=3D"Hyperlink SCXW156866380 BCX0 OWAAutoLink" rel=3D"noreferre=
r noopener" style=3D"color: rgb(239, 62, 66); margin: 0px;">ClamAV
downloads page</a></span><span style=3D"color: rgb(0, 0, 0);">, on the </s=
pan><span style=3D"color: rgb(239, 62, 66);"><a href=3D"https://github.com/=
Cisco-Talos/clamav/releases" target=3D"_blank" id=3D"OWA1b5d5e38-97ee-cd6f-=
277c-dc152b7eac18" class=3D"Hyperlink SCXW156866380 BCX0 OWAAutoLink" rel=
=3D"noreferrer noopener" style=3D"color: rgb(239, 62, 66); margin: 0px;">Gi=
tHub Release
page</a></span><span style=3D"color: rgb(0, 0, 0);">, and through </span><=
span style=3D"color: rgb(239, 62, 66);"><a href=3D"https://hub.docker.com/r=
/clamav/clamav/" target=3D"_blank" id=3D"OWA29f2446b-0dcd-f6ea-b10d-2ecba7e=
b80a8" class=3D"Hyperlink SCXW156866380 BCX0 OWAAutoLink" rel=3D"noreferrer=
noopener" style=3D"color: rgb(239, 62, 66); margin: 0px;">Docker
Hub</a></span><span style=3D"color: rgb(0, 0, 0);">. The images on Docker =
Hub may not be immediately available on release day.</span></div>
<div class=3D"elementToProof" style=3D"direction: ltr; text-align: left; te=
xt-indent: 0px; line-height: 1.4; margin-top: 0px; margin-bottom: 16px; fon=
t-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetic=
a, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
ClamAV 1.5.1 is a patch release with the following fixes:</div>
<ul data-line=3D"9" style=3D"direction: ltr; text-align: left; margin: 0px =
0px 0.7em; padding-right: 2.5em; padding-left: 2.5em; list-style-position: =
initial; list-style-type: disc;">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div class=3D"elementToProof" role=3D"presentation" style=3D"direction: ltr=
; text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 0px; ma=
rgin-bottom: 0.7em;">
Fixed a significant performance issue when scanning some PE files</div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div class=3D"elementToProof" role=3D"presentation" style=3D"direction: ltr=
; text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 0px; ma=
rgin-bottom: 0.7em;">
Fixed an issue recording file entries from a ZIP archive central directory =
which resulted in "Heuristics.Limits.Exceeded.MaxFiles" alerts wh=
en using the ClamScan
<code>--alert-exceeds-max</code> command line option or ClamD <code>Al=
ertExceedsMax</code> config file option</div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div class=3D"elementToProof" role=3D"presentation" style=3D"direction: ltr=
; text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 0px; ma=
rgin-bottom: 0.7em;">
Improved performance when scanning TNEF email attachments</div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div class=3D"elementToProof" role=3D"presentation" style=3D"direction: ltr=
; text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 0px; ma=
rgin-bottom: 0.7em;">
Fixed an issue with recording metadata for OOXML office documents</div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div class=3D"elementToProof" role=3D"presentation" style=3D"direction: ltr=
; text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 0px; ma=
rgin-bottom: 0.7em;">
Fixed an issue with signature matches for VBA in OLE2 office documents</div=
>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div class=3D"elementToProof" role=3D"presentation" style=3D"direction: ltr=
; text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 0px; ma=
rgin-bottom: 0.7em;">
Loosened overly restrictive rules for embedded file identification and incr=
eased the limit for finding PE files embedded in other PE files</div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div class=3D"elementToProof" role=3D"presentation" style=3D"direction: ltr=
; text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 0px; ma=
rgin-bottom: 0.7em;">
Fixed an issue with extracting some RAR archives embedded in other files</d=
iv>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div class=3D"elementToProof" role=3D"presentation" style=3D"direction: ltr=
; text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 0px; ma=
rgin-bottom: 0.7em;">
Fixed an issue with calculating fuzzy hashes affecting some images by updat=
ing the version for several Rust library dependencies</div>
</li><ul data-line=3D"29" style=3D"direction: ltr; text-align: left; margin=
: 0px 0px 0.7em; padding-right: 2.5em; padding-left: 2.5em; list-style-posi=
tion: initial; list-style-type: disc; flex-direction: column; display: flex=
;">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; align-self: start; text-indent: 0px; line-height: 1.4; margin: 0p=
x 0px 0.25em;">
This release does not require a newer version of the Rust compiler toolchai=
n than what was required for ClamAV 1.5.0</li></ul>
</ul>
<div class=3D"elementToProof" style=3D"text-align: left; text-indent: 0px; =
line-height: 1.4; margin-top: 1em; margin-bottom: 1em; font-family: Aptos, =
Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; fo=
nt-size: 12pt;">
<span style=3D"color: rgb(0, 95, 184);"><a href=3D"https://github.com/Cisco=
-Talos/clamav/pull/1606" id=3D"OWAc47ce6a3-376a-7dcf-dd49-5cf12b21dedc" cla=
ss=3D"OWAAutoLink" data-href=3D"https://github.com/Cisco-Talos/clamav/pull/=
1606" style=3D"color: rgb(0, 95, 184);">GitHub
pull request</a></span><span style=3D"color: rgb(0, 0, 0);"> </span><=
/div>
</div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
<br>
</div>
<div id=3D"Signature" class=3D"elementToProof">
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
<br>
</div>
<div class=3D"elementToProof" style=3D"font-family: Calibri, Arial, Helveti=
ca, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Respectfully,</div>
<div class=3D"elementToProof" style=3D"font-family: Calibri, Arial, Helveti=
ca, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Val</div>
<div class=3D"elementToProof" style=3D"font-family: Calibri, Arial, Helveti=
ca, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
<span style=3D"font-family: Helvetica; font-size: 12px;">Valerie Snyder (sh=
e/they)</span><br>
<span style=3D"font-family: Helvetica; font-size: 12px;">ClamAV Development=
</span><br>
<span style=3D"font-family: Helvetica; font-size: 12px;">Talos</span><br>
<span style=3D"font-family: Helvetica; font-size: 12px;">Cisco Systems, Inc=
.</span><br>
</div>
</div>
</body>
</html>
--_000_CH3PR11MB875055C899DD97A8E624C705C6E9ACH3PR11MB8750namp_--
--===============4278828440697883903==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
clamav-announce mailing list
[email protected]
https://lists.clamav.net/mailman/listinfo/clamav-announce
http://www.clamav.net/contact.html#ml
--===============4278828440697883903==--