ClamAV 1.4.2 and 1.0.8 security patch versions published
"Micah Snyder \(micasnyd\) via clamav-users" <[email protected]> Wed, 22 Jan 2025 17:18:20 +0000
| Newsgroups | gmane.comp.security.virus.clamav.user,gmane.comp.security.virus.clamav.devel |
|---|---|
| Message-ID | <CH3PR11MB8750BB65D9999C1C0DA4CFD1C6E12@CH3PR11MB8750.namprd11.prod.outlook.com> |
--===============0326057431325623644==
Content-Language: en-US
Content-Type: multipart/alternative;
boundary="_000_CH3PR11MB8750BB65D9999C1C0DA4CFD1C6E12CH3PR11MB8750namp_"
--_000_CH3PR11MB8750BB65D9999C1C0DA4CFD1C6E12CH3PR11MB8750namp_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
Read this online at https://blog.clamav.net/2025/01/clamav-142-and-108-secu=
rity-patch.html
Today, we are publishing the 1.4.2 and 1.0.8 security patch versions. The r=
elease files for the patch versions are available for download on the ClamA=
V downloads page<https://www.clamav.net/downloads>, on the GitHub Release p=
age<https://github.com/Cisco-Talos/clamav/releases>, and through Docker Hub=
<https://hub.docker.com/r/clamav/clamav/>. The images on Docker Hub may not=
be immediately available on release day. Continue reading to learn what ch=
anged in each version.
1.4.2
ClamAV 1.4.2 is a patch release with the following fixes:
* CVE-2025-20128<https://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2=
025-20128>: Fixed a possible buffer overflow read bug in the OLE2 file pars=
er that could cause a denial-of-service (DoS) condition.
This issue was introduced in version 1.0.0 and affects all currently suppor=
ted versions. It will be fixed in: 1.4.2 and 1.0.8
Thank you to OSS-Fuzz for identifying this issue.
1.0.8
ClamAV 1.0.8 is a patch release with the following fixes:
* CVE-2025-20128<https://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2=
025-20128>: Fixed a possible buffer overflow read bug in the OLE2 file pars=
er that could cause a denial-of-service (DoS) condition.
This issue was introduced in version 1.0.0 and affects all currently suppor=
ted versions. It will be fixed in: 1.4.2 and 1.0.8
Thank you to OSS-Fuzz for identifying this issue.
* ClamOnAcc: Fixed an infinite loop when a watched directory does not e=
xist. This is a backport of a fix from ClamAV 1.3.0.
* GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/142=
6>
Micah Snyder (they/them)
ClamAV Development
Talos
Cisco Systems, Inc.
--_000_CH3PR11MB8750BB65D9999C1C0DA4CFD1C6E12CH3PR11MB8750namp_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<style type=3D"text/css" style=3D"display:none;"> P {margin-top:0;margin-bo=
ttom:0;} </style>
</head>
<body dir=3D"ltr">
<div class=3D"elementToProof" style=3D"line-height: 1.4; margin-top: 1em; m=
argin-bottom: 1em; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServ=
ice, Calibri, Helvetica, sans-serif; font-size: 10pt; color: rgb(0, 0, 0);"=
>
Read this online at <a href=3D"https://blog.clamav.net/2025/01/clamav-142-a=
nd-108-security-patch.html" id=3D"LPlnk210962" class=3D"elementToProof">
https://blog.clamav.net/2025/01/clamav-142-and-108-security-patch.html</a><=
/div>
<div class=3D"elementToProof" style=3D"line-height: 1.4; margin-top: 1em; m=
argin-bottom: 1em; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServ=
ice, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);"=
>
<br>
</div>
<div class=3D"elementToProof" style=3D"line-height: 1.4; margin-top: 1em; m=
argin-bottom: 1em; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServ=
ice, Calibri, Helvetica, sans-serif; font-size: 12pt;">
<span style=3D"color: rgb(0, 0, 0);">Today, we are publishing the 1.4.2 and=
1.0.8 security patch versions. The release files for the patch versions ar=
e available for download on the
</span><span style=3D"color: rgb(239, 62, 66);"><a href=3D"https://www.clam=
av.net/downloads" target=3D"_blank" id=3D"OWAd6ad61ad-c4bd-b498-b52c-8fa9c2=
663066" class=3D"Hyperlink SCXW156866380 BCX0 OWAAutoLink" rel=3D"noreferre=
r noopener" style=3D"color: rgb(239, 62, 66); margin: 0px;">ClamAV
downloads page</a></span><span style=3D"color: rgb(0, 0, 0);">, on the </s=
pan><span style=3D"color: rgb(239, 62, 66);"><a href=3D"https://github.com/=
Cisco-Talos/clamav/releases" target=3D"_blank" id=3D"OWAa5a5bcc4-c580-6191-=
f110-9129d71015ac" class=3D"Hyperlink SCXW156866380 BCX0 OWAAutoLink" rel=
=3D"noreferrer noopener" style=3D"color: rgb(239, 62, 66); margin: 0px;">Gi=
tHub Release
page</a></span><span style=3D"color: rgb(0, 0, 0);">, and through </span><=
span style=3D"color: rgb(239, 62, 66);"><a href=3D"https://hub.docker.com/r=
/clamav/clamav/" target=3D"_blank" id=3D"OWA0ac14a77-a665-31bb-5d42-1134cb2=
22391" class=3D"Hyperlink SCXW156866380 BCX0 OWAAutoLink" rel=3D"noreferrer=
noopener" style=3D"color: rgb(239, 62, 66); margin: 0px;">Docker
Hub</a></span><span style=3D"color: rgb(0, 0, 0);">. The images on Docker =
Hub may not be immediately available on release day. Continue reading to le=
arn what changed in each version.</span></div>
<div style=3D"line-height: 1.4; margin: 0px; font-family: Aptos, Aptos_Embe=
ddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 1=
2pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style=3D"direction: ltr; text-align: left; line-height: normal; margin=
: 0px 0px 30px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService=
, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<b>1.4.2</b></div>
<div style=3D"direction: ltr; line-height: 1.4; margin-right: 0px; margin-l=
eft: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Cali=
bri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
ClamAV 1.4.2 is a patch release with the following fixes: </div>
<ul style=3D"direction: ltr; text-align: left; margin: 0.5em 0px; padding-r=
ight: 2.5em; padding-left: 2.5em; list-style-position: initial; list-style-=
type: disc;">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; line-height: 1.4; margin: 0px 0px 0.25em;">
<span style=3D"color: rgb(239, 62, 66);"><a href=3D"https://cve.mitre.org/c=
gi-bin/cvename.cgi?name=3DCVE-2025-20128" target=3D"_blank" id=3D"OWAa7e4ef=
9a-90e5-1ed9-6c8a-22844ca85a0f" class=3D"OWAAutoLink" rel=3D"nofollow" styl=
e=3D"color: rgb(239, 62, 66);">CVE-2025-20128</a></span>:
Fixed a possible buffer overflow read bug in the OLE2 file parser that cou=
ld cause a denial-of-service (DoS) condition.<br>
<br>
This issue was introduced in version 1.0.0 and affects all currently suppor=
ted versions. It will be fixed in: 1.4.2 and 1.0.8<br>
<br>
Thank you to OSS-Fuzz for identifying this issue.<br>
<br>
</li></ul>
<div style=3D"direction: ltr; text-align: left; line-height: normal; margin=
: 0px 0px 30px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService=
, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<b>1.0.8</b></div>
<div style=3D"direction: ltr; line-height: 1.4; margin-right: 0px; margin-l=
eft: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Cali=
bri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
ClamAV 1.0.8 is a patch release with the following fixes:</div>
<ul style=3D"direction: ltr; text-align: left; margin: 0.5em 0px; padding-r=
ight: 2.5em; padding-left: 2.5em; list-style-position: initial; list-style-=
type: disc;">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; line-height: 1.4; margin: 0px 0px 0.25em;">
<span style=3D"color: rgb(239, 62, 66);"><a href=3D"https://cve.mitre.org/c=
gi-bin/cvename.cgi?name=3DCVE-2025-20128" target=3D"_blank" id=3D"OWAb73a8e=
74-8366-22f5-3666-d3129781e681" class=3D"OWAAutoLink" rel=3D"nofollow" styl=
e=3D"color: rgb(239, 62, 66);">CVE-2025-20128</a></span>:
Fixed a possible buffer overflow read bug in the OLE2 file parser that cou=
ld cause a denial-of-service (DoS) condition.<br>
<br>
This issue was introduced in version 1.0.0 and affects all currently suppor=
ted versions. It will be fixed in: 1.4.2 and 1.0.8<br>
<br>
Thank you to OSS-Fuzz for identifying this issue.<br>
<br>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; line-height: 1.4; margin: 0px 0px 0.25em;"=
>
ClamOnAcc: Fixed an infinite loop when a watched directory does not exist. =
This is a backport of a fix from ClamAV 1.3.0.</li><ul style=3D"direction: =
ltr; margin: 0.5em 0px; padding-right: 2.5em; padding-left: 2.5em; list-sty=
le-position: initial; list-style-type: disc;">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; line-height: 1.4; margin: 0px 0px 0.25em;">
<span style=3D"color: rgb(239, 62, 66);"><a href=3D"https://github.com/Cisc=
o-Talos/clamav/pull/1426" target=3D"_blank" id=3D"OWA52bd98b9-732c-dbbd-b46=
9-dd97806378c8" class=3D"OWAAutoLink" rel=3D"nofollow" style=3D"color: rgb(=
239, 62, 66);">GitHub pull request</a></span></li></ul>
</ul>
<div style=3D"margin: 1.5em 0px 0px;">
<div style=3D"text-align: left; text-indent: 0px; line-height: 1.6; font-fa=
mily: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, s=
ans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class=3D"elementToProof" style=3D"text-align: left; text-indent: 0px; =
line-height: 1.6; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
</div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
<br>
</div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
<br>
</div>
<div id=3D"Signature" class=3D"elementToProof">
<div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0);">
<br>
<span style=3D"font-family: Helvetica; font-size: 12px;">Micah Snyder (they=
/them)</span><br>
<span style=3D"font-family: Helvetica; font-size: 12px;">ClamAV Development=
</span><br>
<span style=3D"font-family: Helvetica; font-size: 12px;">Talos</span></div>
<div style=3D"font-family: Helvetica; font-size: 12px; color: rgb(0, 0, 0);=
">Cisco Systems, Inc.</div>
</div>
</body>
</html>
--_000_CH3PR11MB8750BB65D9999C1C0DA4CFD1C6E12CH3PR11MB8750namp_--
--===============0326057431325623644==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
Manage your clamav-users mailing list subscription / unsubscribe:
https://lists.clamav.net/mailman/listinfo/clamav-users
Help us build a comprehensive ClamAV guide:
https://github.com/Cisco-Talos/clamav-documentation
https://docs.clamav.net/#mailing-lists-and-chat
--===============0326057431325623644==--