ClamAV 1.3.1, 1.2.3, 1.0.6 patch versions published

"Micah Snyder (micasnyd)" <[email protected]> Wed, 17 Apr 2024 17:34:24 +0000
Newsgroups gmane.comp.security.virus.clamav.devel,gmane.comp.security.virus.clamav.win32
Message-ID <CH3PR11MB87507F3E9B6994963056076CC60F2@CH3PR11MB8750.namprd11.prod.outlook.com>
Read this online at: https://blog.clamav.net/2024/04/clamav-131-123-106-pat=
ch-versions.html




Today, we are publishing the 1.3.1, 1.2.3, and 1.0.6 security patch version=
s.

The release files for the patch versions are available for download on the =
ClamAV downloads page<https://www.clamav.net/downloads>, on the GitHub Rele=
ase page<https://github.com/Cisco-Talos/clamav/releases>, and through Docke=
r Hub<https://hub.docker.com/r/clamav/clamav/>.

The images on Docker Hub may not be immediately available on release day.

Continue reading to learn what changed in each version.

1.3.1

ClamAV 1.3.1 is a critical patch release with the following fixes:

  *   CVE-2024-20380<https://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2=
024-20380>: Fixed a possible crash in the HTML file parser that could cause=
 a denial-of-service (DoS) condition.

This issue affects version 1.3.0 only and does not affect prior versions.

Thank you to B=B3a=BFej Paw=B3owski for identifying this issue.

     *   GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/124=
2>
  *   Updated select Rust dependencies to the latest versions. This resolve=
d Cargo audit complaints and included PNG parser bug fixes.

     *   GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/122=
7>
  *   Fixed a bug causing some text to be truncated when converting from UT=
F-16.

     *   GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/123=
0>
  *   Fixed assorted complaints identified by Coverity static analysis.

     *   GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/123=
5>
  *   Fixed a bug causing CVDs downloaded by the DatabaseCustomURL Freshcla=
m config option to be pruned and then re-downloaded with every update.

     *   GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/123=
8>
  *   Added the new 'valhalla' database name to the list of optional databa=
ses in preparation for future work.

     *   GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/123=
8>
  *   Added symbols to the libclamav.map file to enable additional build co=
nfigurations.

Patch courtesy of Neil Wilson.

     *   GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/124=
4>

1.2.3

ClamAV 1.2.3 is a critical patch release with the following fixes:

  *   Updated select Rust dependencies to the latest versions. This resolve=
d Cargo audit complaints and included PNG parser bug fixes.

     *   GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/122=
6>
  *   Fixed a bug causing some text to be truncated when converting from UT=
F-16.

     *   GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/123=
1>
  *   Fixed assorted complaints identified by Coverity static analysis.

     *   GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/123=
6>
  *   Fixed a bug causing CVDs downloaded by the DatabaseCustomURL Freshcla=
m config option to be pruned and then re-downloaded with every update.

     *   GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/123=
9>
  *   Added the new 'valhalla' database name to the list of optional databa=
ses in preparation for future work.

     *   GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/123=
9>
  *   Silenced a warning "Unexpected early end-of-file" that occured when s=
canning some PNG files.

     *   GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/121=
5>

1.0.6

ClamAV 1.0.6 is a critical patch release with the following fixes:

  *   Updated select Rust dependencies to the latest versions. This resolve=
d Cargo audit complaints and included PNG parser bug fixes.

     *   GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/122=
5>
  *   Fixed a bug causing some text to be truncated when converting from UT=
F-16.

     *   GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/123=
2>
  *   Fixed assorted complaints identified by Coverity static analysis.

     *   GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/123=
7>
  *   Fixed a bug causing CVDs downloaded by the DatabaseCustomURL Freshcla=
m config option to be pruned and then re-downloaded with every update.

     *   GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/124=
0>
  *   Added the new 'valhalla' database name to the list of optional databa=
ses in preparation for future work.

     *   GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/124=
0>
  *   Silenced a warning "Unexpected early end-of-file" that occured when s=
canning some PNG files.

     *   GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/121=
6>





Micah Snyder (they/them)
ClamAV Development
Talos
Cisco Systems, Inc.
_______________________________________________

clamav-devel mailing list
[email protected]
https://lists.clamav.net/mailman/listinfo/clamav-devel

Please submit your patches to our Github: https://github.com/Cisco-Talos/cl=
amav-devel/pulls

Help us build a comprehensive ClamAV guide:
https://github.com/vrtadmin/clamav-faq

http://www.clamav.net/contact.html#ml