ClamAV 1.3.1, 1.2.3, 1.0.6 patch versions published
"Micah Snyder (micasnyd)" <[email protected]> Wed, 17 Apr 2024 17:34:24 +0000
| Newsgroups | gmane.comp.security.virus.clamav.devel,gmane.comp.security.virus.clamav.win32 |
|---|---|
| Message-ID | <CH3PR11MB87507F3E9B6994963056076CC60F2@CH3PR11MB8750.namprd11.prod.outlook.com> |
Read this online at: https://blog.clamav.net/2024/04/clamav-131-123-106-pat=
ch-versions.html
Today, we are publishing the 1.3.1, 1.2.3, and 1.0.6 security patch version=
s.
The release files for the patch versions are available for download on the =
ClamAV downloads page<https://www.clamav.net/downloads>, on the GitHub Rele=
ase page<https://github.com/Cisco-Talos/clamav/releases>, and through Docke=
r Hub<https://hub.docker.com/r/clamav/clamav/>.
The images on Docker Hub may not be immediately available on release day.
Continue reading to learn what changed in each version.
1.3.1
ClamAV 1.3.1 is a critical patch release with the following fixes:
* CVE-2024-20380<https://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2=
024-20380>: Fixed a possible crash in the HTML file parser that could cause=
a denial-of-service (DoS) condition.
This issue affects version 1.3.0 only and does not affect prior versions.
Thank you to B=B3a=BFej Paw=B3owski for identifying this issue.
* GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/124=
2>
* Updated select Rust dependencies to the latest versions. This resolve=
d Cargo audit complaints and included PNG parser bug fixes.
* GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/122=
7>
* Fixed a bug causing some text to be truncated when converting from UT=
F-16.
* GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/123=
0>
* Fixed assorted complaints identified by Coverity static analysis.
* GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/123=
5>
* Fixed a bug causing CVDs downloaded by the DatabaseCustomURL Freshcla=
m config option to be pruned and then re-downloaded with every update.
* GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/123=
8>
* Added the new 'valhalla' database name to the list of optional databa=
ses in preparation for future work.
* GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/123=
8>
* Added symbols to the libclamav.map file to enable additional build co=
nfigurations.
Patch courtesy of Neil Wilson.
* GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/124=
4>
1.2.3
ClamAV 1.2.3 is a critical patch release with the following fixes:
* Updated select Rust dependencies to the latest versions. This resolve=
d Cargo audit complaints and included PNG parser bug fixes.
* GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/122=
6>
* Fixed a bug causing some text to be truncated when converting from UT=
F-16.
* GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/123=
1>
* Fixed assorted complaints identified by Coverity static analysis.
* GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/123=
6>
* Fixed a bug causing CVDs downloaded by the DatabaseCustomURL Freshcla=
m config option to be pruned and then re-downloaded with every update.
* GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/123=
9>
* Added the new 'valhalla' database name to the list of optional databa=
ses in preparation for future work.
* GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/123=
9>
* Silenced a warning "Unexpected early end-of-file" that occured when s=
canning some PNG files.
* GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/121=
5>
1.0.6
ClamAV 1.0.6 is a critical patch release with the following fixes:
* Updated select Rust dependencies to the latest versions. This resolve=
d Cargo audit complaints and included PNG parser bug fixes.
* GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/122=
5>
* Fixed a bug causing some text to be truncated when converting from UT=
F-16.
* GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/123=
2>
* Fixed assorted complaints identified by Coverity static analysis.
* GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/123=
7>
* Fixed a bug causing CVDs downloaded by the DatabaseCustomURL Freshcla=
m config option to be pruned and then re-downloaded with every update.
* GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/124=
0>
* Added the new 'valhalla' database name to the list of optional databa=
ses in preparation for future work.
* GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/124=
0>
* Silenced a warning "Unexpected early end-of-file" that occured when s=
canning some PNG files.
* GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/121=
6>
Micah Snyder (they/them)
ClamAV Development
Talos
Cisco Systems, Inc.
_______________________________________________
clamav-devel mailing list
[email protected]
https://lists.clamav.net/mailman/listinfo/clamav-devel
Please submit your patches to our Github: https://github.com/Cisco-Talos/cl=
amav-devel/pulls
Help us build a comprehensive ClamAV guide:
https://github.com/vrtadmin/clamav-faq
http://www.clamav.net/contact.html#ml