ClamAV 1.4.3 and 1.0.9 security patch versions published
"Val Snyder \(micasnyd\) via clamav-users" <[email protected]> Wed, 18 Jun 2025 16:27:27 +0000
| Newsgroups | gmane.comp.security.virus.clamav.user,gmane.comp.security.virus.clamav.devel |
|---|---|
| Message-ID | <CH3PR11MB875069A1C091F03C320AE8CBC672A@CH3PR11MB8750.namprd11.prod.outlook.com> |
--===============5255304534469298450==
Content-Language: en-US
Content-Type: multipart/alternative;
boundary="_000_CH3PR11MB875069A1C091F03C320AE8CBC672ACH3PR11MB8750namp_"
--_000_CH3PR11MB875069A1C091F03C320AE8CBC672ACH3PR11MB8750namp_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
Read this online at: https://blog.clamav.net/2025/06/clamav-143-and-109-sec=
urity-patch.html
Today, we are publishing the 1.4.3 and 1.0.9 security patch versions.
We have also added Linux aarch64 (aka ARM64) RPM and DEB installer packages=
for the 1.4 LTS release.
The release files for the patch versions are available for download on the =
ClamAV downloads page<https://www.clamav.net/downloads>, on the GitHub Rele=
ase page<https://github.com/Cisco-Talos/clamav/releases>, and through Docke=
r Hub<https://hub.docker.com/r/clamav/clamav/>. The images on Docker Hub ma=
y not be immediately available on release day. Continue reading to learn wh=
at changed in each version.
1.4.3
ClamAV 1.4.3 is a patch release with the following fixes:
*
CVE-2025-20260<https://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2025-20=
260>: Fixed a possible buffer overflow write bug in the PDF file parser tha=
t could cause a denial-of-service (DoS) condition or enable remote code exe=
cution.
This issue only affects configurations where both:
The code flaw was present prior to version 1.0.0, but a change in version 1=
.0.0 that enables larger allocations based on untrusted data made it possib=
le to trigger this bug.
This issue affects all currently supported versions. It will be fixed in:
Thank you to Greg Walkup at Sandia National Labs for identifying this issue=
.
* The max file-size scan limit is set greater than or equal to 1024M=
B.
* The max scan-size scan limit is set greater than or equal to 1025M=
B.
* 1.4.3
* 1.0.9
*
CVE-2025-20234<https://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2025-20=
234>: Fixed a possible buffer overflow read bug in the UDF file parser that=
may write to a temp file and thus disclose information, or it may crash an=
d cause a denial-of-service (DoS) condition.
This issue was introduced in version 1.2.0. It will be fixed in 1.4.3.
Thank you to volticks (@movx64 on Twitter/X), working with Trend Micro Zero=
Day Initiative, for identifying this issue.
*
Fixed a possible use-after-free bug in the Xz decompression module in the b=
undled lzma-sdk library.
This issue was fixed in the lzma-sdk version 18.03. ClamAV bundles a copy o=
f the lzma-sdk with some performance changes specific to libclamav, plus se=
lect bug fixes like this one in lieu of a full upgrade to newer lzma-sdk.
This issue affects all ClamAV versions at least as far back as 0.99.4. It w=
ill be fixed in:
Thank you to OSS-Fuzz for identifying this issue.
* 1.4.3
* 1.0.9
*
Windows: Fixed a build install issue when a DLL dependency such as libcrypt=
o has the exact same name as one provided by the Windows operating system.
1.0.9
ClamAV 1.0.9 is a patch release with the following fixes:
*
CVE-2025-20260<https://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2025-20=
260>: Fixed a possible buffer overflow write bug in the PDF file parser tha=
t could cause a denial-of-service (DoS) condition or enable remote code exe=
cution.
This issue only affects configurations where both:
The code flaw was present prior to version 1.0.0, but a change in version 1=
.0.0 that enables larger allocations based on untrusted data made it possib=
le to trigger this bug.
This issue affects all currently supported versions. It will be fixed in:
Thank you to Greg Walkup at Sandia National Labs for identifying this issue=
.
* The max file-size scan limit is set greater than or equal to 1024M=
B.
* The max scan-size scan limit is set greater than or equal to 1025M=
B.
* 1.4.3
* 1.0.9
*
Fixed a possible use-after-free bug in the Xz decompression module in the b=
undled lzma-sdk library.
This issue was fixed in the lzma-sdk version 18.03. ClamAV bundles a copy o=
f the lzma-sdk with some performance changes specific to libclamav, plus se=
lect bug fixes like this one in lieu of a full upgrade to newer lzma-sdk.
This issue affects all ClamAV versions at least as far back as 0.99.4. It w=
ill be fixed in:
Thank you to OSS-Fuzz for identifying this issue.
* 1.4.3
* 1.0.9
*
Windows: Fixed a build install issue when a DLL dependency such as libcrypt=
o has the exact same name as one provided by the Windows operating system.
Val Snyder (she/they)
ClamAV Development
Talos
Cisco Systems, Inc.
--_000_CH3PR11MB875069A1C091F03C320AE8CBC672ACH3PR11MB8750namp_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<style type=3D"text/css" style=3D"display:none;"> P {margin-top:0;margin-bo=
ttom:0;} </style>
</head>
<body dir=3D"ltr">
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 10pt; c=
olor: rgb(0, 0, 0);">
Read this online at: <a href=3D"https://blog.clamav.net/2025/06/clamav-143-=
and-109-security-patch.html" id=3D"LPlnk285985">
https://blog.clamav.net/2025/06/clamav-143-and-109-security-patch.html</a><=
/div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 10pt; c=
olor: rgb(0, 0, 0);">
<br>
</div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
<br>
</div>
<div id=3D"post-body-5757976465642022177" class=3D"elementToProof">
<div class=3D"elementToProof" style=3D"text-align: left; text-indent: 0px; =
line-height: 1.4; margin-top: 1em; margin-bottom: 1em; font-family: Aptos, =
Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; fo=
nt-size: 12pt; color: rgb(0, 0, 0);">
Today, we are publishing the 1.4.3 and 1.0.9 security patch versions.</div>
<div class=3D"elementToProof" style=3D"text-align: left; text-indent: 0px; =
line-height: 1.4; margin-top: 1em; margin-bottom: 1em; font-family: Aptos, =
Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; fo=
nt-size: 12pt; color: rgb(0, 0, 0);">
We have also added Linux aarch64 (aka ARM64) RPM and DEB installer packages=
for the 1.4 LTS release.</div>
<div class=3D"elementToProof" style=3D"text-align: left; text-indent: 0px; =
line-height: 1.4; margin-top: 1em; margin-bottom: 1em; font-family: Aptos, =
Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; fo=
nt-size: 12pt;">
<span style=3D"color: rgb(0, 0, 0);">The release files for the patch versio=
ns are available for download on the
</span><span style=3D"color: rgb(239, 62, 66);"><a href=3D"https://www.clam=
av.net/downloads" target=3D"_blank" id=3D"OWAb7691f33-cea0-4fb5-9c6c-dd7eb9=
02781f" class=3D"Hyperlink SCXW156866380 BCX0 OWAAutoLink" rel=3D"noreferre=
r noopener" style=3D"color: rgb(239, 62, 66); margin: 0px;">ClamAV
downloads page</a></span><span style=3D"color: rgb(0, 0, 0);">, on the </s=
pan><span style=3D"color: rgb(239, 62, 66);"><a href=3D"https://github.com/=
Cisco-Talos/clamav/releases" target=3D"_blank" id=3D"OWA350371fc-5c02-4f27-=
728c-a25c3b834dbc" class=3D"Hyperlink SCXW156866380 BCX0 OWAAutoLink" rel=
=3D"noreferrer noopener" style=3D"color: rgb(239, 62, 66); margin: 0px;">Gi=
tHub Release
page</a></span><span style=3D"color: rgb(0, 0, 0);">, and through </span><=
span style=3D"color: rgb(239, 62, 66);"><a href=3D"https://hub.docker.com/r=
/clamav/clamav/" target=3D"_blank" id=3D"OWA44b9b7a8-2436-ff05-ba4c-fc3a7c5=
0f451" class=3D"Hyperlink SCXW156866380 BCX0 OWAAutoLink" rel=3D"noreferrer=
noopener" style=3D"color: rgb(239, 62, 66); margin: 0px;">Docker
Hub</a></span><span style=3D"color: rgb(0, 0, 0);">. The images on Docker =
Hub may not be immediately available on release day. Continue reading to le=
arn what changed in each version.</span></div>
<div class=3D"elementToProof" style=3D"direction: ltr; text-align: left; te=
xt-indent: 0px; line-height: normal; margin: 0px 0px 30px; font-family: Apt=
os, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif=
; font-size: 12pt; color: rgb(0, 0, 0);">
<b>1.4.3</b></div>
<div class=3D"elementToProof" style=3D"direction: ltr; text-align: left; te=
xt-indent: 0px; line-height: 1.4; margin-right: 0px; margin-left: 0px; font=
-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica=
, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
ClamAV 1.4.3 is a patch release with the following fixes: </div>
<ul style=3D"direction: ltr; text-align: left; margin: 0.5em 0px; padding-r=
ight: 2.5em; padding-left: 2.5em; list-style-position: initial; list-style-=
type: disc;">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); text-i=
ndent: 0px; margin: 0px 0px 0.25em;">
<div class=3D"elementToProof" role=3D"presentation" style=3D"direction: ltr=
; text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 16px; m=
argin-bottom: 16px;">
<span style=3D"color: rgb(9, 105, 218);"><a href=3D"https://cve.mitre.org/c=
gi-bin/cvename.cgi?name=3DCVE-2025-20260" id=3D"OWA87651017-4bef-52d8-2519-=
c75a449fe46f" class=3D"OWAAutoLink" rel=3D"nofollow" style=3D"color: rgb(9,=
105, 218);">CVE-2025-20260</a></span>: Fixed
a possible buffer overflow write bug in the PDF file parser that could cau=
se a denial-of-service (DoS) condition or enable remote code execution.</di=
v>
<div class=3D"elementToProof" role=3D"presentation" style=3D"direction: ltr=
; text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 16px; m=
argin-bottom: 16px;">
This issue only affects configurations where both:</div>
<div class=3D"elementToProof" role=3D"presentation" style=3D"direction: ltr=
; text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 16px; m=
argin-bottom: 16px;">
The code flaw was present prior to version 1.0.0, but a change in version 1=
.0.0 that enables larger allocations based on untrusted data made it possib=
le to trigger this bug.</div>
<div class=3D"elementToProof" role=3D"presentation" style=3D"direction: ltr=
; text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 16px; m=
argin-bottom: 16px;">
This issue affects all currently supported versions. It will be fixed in:</=
div>
<div class=3D"elementToProof" role=3D"presentation" style=3D"direction: ltr=
; text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 16px; m=
argin-bottom: 16px;">
Thank you to Greg Walkup at Sandia National Labs for identifying this issue=
.</div>
</li><ol start=3D"1" style=3D"direction: ltr; text-align: left; margin-top:=
0px; margin-bottom: 0px; padding-left: 2em; list-style-type: lower-roman; =
flex-direction: column; display: flex;">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; align-self: start; text-indent: 0px; line-height: 1.4; margin: 0p=
x 0px 0.25em;">
The max file-size scan limit is set greater than or equal to 1024MB.</li><l=
i style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Cal=
ibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); directio=
n: ltr; align-self: start; text-indent: 0px; line-height: 1.4; margin: 0.25=
em 0px;">
The max scan-size scan limit is set greater than or equal to 1025MB.</li></=
ol>
<ul style=3D"direction: ltr; text-align: left; margin: 0px; padding-right: =
2.5em; padding-left: 2em; list-style-position: initial; list-style-type: di=
sc; flex-direction: column; display: flex;">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; align-self: start; text-indent: 0px; line-height: 1.4; margin: 0p=
x 0px 0.25em;">
1.4.3</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFont=
Service, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, =
0); direction: ltr; align-self: start; text-indent: 0px; line-height: 1.4; =
margin: 0.25em 0px;">
1.0.9</li></ul>
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); text-i=
ndent: 0px; margin: 0.25em 0px;">
<div class=3D"elementToProof" role=3D"presentation" style=3D"direction: ltr=
; text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 16px; m=
argin-bottom: 16px;">
<span style=3D"color: rgb(9, 105, 218);"><a href=3D"https://cve.mitre.org/c=
gi-bin/cvename.cgi?name=3DCVE-2025-20234" id=3D"OWA9a555157-36c4-86bd-56c5-=
0e28e43d0463" class=3D"OWAAutoLink" rel=3D"nofollow" style=3D"color: rgb(9,=
105, 218);">CVE-2025-20234</a></span>: Fixed
a possible buffer overflow read bug in the UDF file parser that may write =
to a temp file and thus disclose information, or it may crash and cause a d=
enial-of-service (DoS) condition.</div>
<div class=3D"elementToProof" role=3D"presentation" style=3D"direction: ltr=
; text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 16px; m=
argin-bottom: 16px;">
This issue was introduced in version 1.2.0. It will be fixed in 1.4.3.</div=
>
<div class=3D"elementToProof" role=3D"presentation" style=3D"direction: ltr=
; text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 16px; m=
argin-bottom: 16px;">
Thank you to volticks (@movx64 on Twitter/X), working with Trend Micro Zero=
Day Initiative, for identifying this issue.</div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); t=
ext-indent: 0px; margin: 0.25em 0px;">
<div class=3D"elementToProof" role=3D"presentation" style=3D"direction: ltr=
; text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 16px; m=
argin-bottom: 16px;">
Fixed a possible use-after-free bug in the Xz decompression module in the b=
undled lzma-sdk library.</div>
<div class=3D"elementToProof" role=3D"presentation" style=3D"direction: ltr=
; text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 16px; m=
argin-bottom: 16px;">
This issue was fixed in the lzma-sdk version 18.03. ClamAV bundles a copy o=
f the lzma-sdk with some performance changes specific to libclamav, plus se=
lect bug fixes like this one in lieu of a full upgrade to newer lzma-sdk.</=
div>
<div class=3D"elementToProof" role=3D"presentation" style=3D"direction: ltr=
; text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 16px; m=
argin-bottom: 16px;">
This issue affects all ClamAV versions at least as far back as 0.99.4. It w=
ill be fixed in:</div>
<div class=3D"elementToProof" role=3D"presentation" style=3D"direction: ltr=
; text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 16px; m=
argin-bottom: 16px;">
Thank you to OSS-Fuzz for identifying this issue.</div>
</li><ul style=3D"direction: ltr; text-align: left; margin: 0px; padding-ri=
ght: 2.5em; padding-left: 2em; list-style-position: initial; list-style-typ=
e: disc; flex-direction: column; display: flex;">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; align-self: start; text-indent: 0px; line-height: 1.4; margin: 0p=
x 0px 0.25em;">
1.4.3</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFont=
Service, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, =
0); direction: ltr; align-self: start; text-indent: 0px; line-height: 1.4; =
margin: 0.25em 0px;">
1.0.9</li></ul>
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); text-i=
ndent: 0px; margin: 0.25em 0px;">
<div class=3D"elementToProof" role=3D"presentation" style=3D"direction: ltr=
; text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 16px; m=
argin-bottom: 16px;">
Windows: Fixed a build install issue when a DLL dependency such as libcrypt=
o has the exact same name as one provided by the Windows operating system.<=
/div>
</li></ul>
<div class=3D"elementToProof" style=3D"direction: ltr; text-align: left; te=
xt-indent: 0px; line-height: normal; margin: 0px 0px 30px; font-family: Apt=
os, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif=
; font-size: 12pt; color: rgb(0, 0, 0);">
<b>1.0.9</b></div>
<div class=3D"elementToProof" style=3D"direction: ltr; text-align: left; te=
xt-indent: 0px; line-height: 1.4; margin-right: 0px; margin-left: 0px; font=
-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica=
, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
ClamAV 1.0.9 is a patch release with the following fixes:</div>
<ul style=3D"direction: ltr; text-align: left; margin: 0px 0px 16px; paddin=
g-right: 2.5em; padding-left: 2em; list-style-position: initial; list-style=
-type: disc;">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); text-i=
ndent: 0px; margin: 0px 0px 0.25em;">
<div class=3D"elementToProof" role=3D"presentation" style=3D"direction: ltr=
; text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 16px; m=
argin-bottom: 16px;">
<span style=3D"color: rgb(9, 105, 218);"><a href=3D"https://cve.mitre.org/c=
gi-bin/cvename.cgi?name=3DCVE-2025-20260" id=3D"OWAb05bedc6-8a7c-4815-5797-=
96248878d31a" class=3D"OWAAutoLink" rel=3D"nofollow" style=3D"color: rgb(9,=
105, 218);">CVE-2025-20260</a></span>: Fixed
a possible buffer overflow write bug in the PDF file parser that could cau=
se a denial-of-service (DoS) condition or enable remote code execution.</di=
v>
<div class=3D"elementToProof" role=3D"presentation" style=3D"direction: ltr=
; text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 16px; m=
argin-bottom: 16px;">
This issue only affects configurations where both:</div>
<div class=3D"elementToProof" role=3D"presentation" style=3D"direction: ltr=
; text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 16px; m=
argin-bottom: 16px;">
The code flaw was present prior to version 1.0.0, but a change in version 1=
.0.0 that enables larger allocations based on untrusted data made it possib=
le to trigger this bug.</div>
<div class=3D"elementToProof" role=3D"presentation" style=3D"direction: ltr=
; text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 16px; m=
argin-bottom: 16px;">
This issue affects all currently supported versions. It will be fixed in:</=
div>
<div class=3D"elementToProof" role=3D"presentation" style=3D"direction: ltr=
; text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 16px; m=
argin-bottom: 16px;">
Thank you to Greg Walkup at Sandia National Labs for identifying this issue=
.</div>
</li><ol start=3D"1" style=3D"direction: ltr; text-align: left; margin-top:=
0px; margin-bottom: 0px; padding-left: 2em; list-style-type: lower-roman; =
flex-direction: column; display: flex;">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; align-self: start; text-indent: 0px; line-height: 1.4; margin: 0p=
x 0px 0.25em;">
The max file-size scan limit is set greater than or equal to 1024MB.</li><l=
i style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Cal=
ibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); directio=
n: ltr; align-self: start; text-indent: 0px; line-height: 1.4; margin: 0.25=
em 0px;">
The max scan-size scan limit is set greater than or equal to 1025MB.</li></=
ol>
<ul style=3D"direction: ltr; text-align: left; margin: 0px; padding-right: =
2.5em; padding-left: 2em; list-style-position: initial; list-style-type: di=
sc; flex-direction: column; display: flex;">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; align-self: start; text-indent: 0px; line-height: 1.4; margin: 0p=
x 0px 0.25em;">
1.4.3</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFont=
Service, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, =
0); direction: ltr; align-self: start; text-indent: 0px; line-height: 1.4; =
margin: 0.25em 0px;">
1.0.9</li></ul>
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); text-i=
ndent: 0px; margin: 0.25em 0px;">
<div class=3D"elementToProof" role=3D"presentation" style=3D"direction: ltr=
; text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 16px; m=
argin-bottom: 16px;">
Fixed a possible use-after-free bug in the Xz decompression module in the b=
undled lzma-sdk library.</div>
<div class=3D"elementToProof" role=3D"presentation" style=3D"direction: ltr=
; text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 16px; m=
argin-bottom: 16px;">
This issue was fixed in the lzma-sdk version 18.03. ClamAV bundles a copy o=
f the lzma-sdk with some performance changes specific to libclamav, plus se=
lect bug fixes like this one in lieu of a full upgrade to newer lzma-sdk.</=
div>
<div class=3D"elementToProof" role=3D"presentation" style=3D"direction: ltr=
; text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 16px; m=
argin-bottom: 16px;">
This issue affects all ClamAV versions at least as far back as 0.99.4. It w=
ill be fixed in:</div>
<div class=3D"elementToProof" role=3D"presentation" style=3D"direction: ltr=
; text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 16px; m=
argin-bottom: 16px;">
Thank you to OSS-Fuzz for identifying this issue.</div>
</li><ul style=3D"direction: ltr; text-align: left; margin: 0px; padding-ri=
ght: 2.5em; padding-left: 2em; list-style-position: initial; list-style-typ=
e: disc; flex-direction: column; display: flex;">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; align-self: start; text-indent: 0px; line-height: 1.4; margin: 0p=
x 0px 0.25em;">
1.4.3</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFont=
Service, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, =
0); direction: ltr; align-self: start; text-indent: 0px; line-height: 1.4; =
margin: 0.25em 0px;">
1.0.9</li></ul>
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); text-i=
ndent: 0px; margin: 0.25em 0px;">
<div class=3D"elementToProof" role=3D"presentation" style=3D"direction: ltr=
; text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 16px; m=
argin-bottom: 16px;">
Windows: Fixed a build install issue when a DLL dependency such as libcrypt=
o has the exact same name as one provided by the Windows operating system.<=
/div>
</li></ul>
</div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
<br>
</div>
<div id=3D"Signature" class=3D"elementToProof">
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
<br>
</div>
<div class=3D"elementToProof" style=3D"font-family: Calibri, Arial, Helveti=
ca, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
<span style=3D"font-family: Helvetica; font-size: 12px;">Val Snyder (she/th=
ey)</span><br>
<span style=3D"font-family: Helvetica; font-size: 12px;">ClamAV Development=
</span><br>
<span style=3D"font-family: Helvetica; font-size: 12px;">Talos</span><br>
<span style=3D"font-family: Helvetica; font-size: 12px;">Cisco Systems, Inc=
.</span><br>
</div>
</div>
</body>
</html>
--_000_CH3PR11MB875069A1C091F03C320AE8CBC672ACH3PR11MB8750namp_--
--===============5255304534469298450==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
Manage your clamav-users mailing list subscription / unsubscribe:
https://lists.clamav.net/mailman/listinfo/clamav-users
Help us build a comprehensive ClamAV guide:
https://github.com/Cisco-Talos/clamav-documentation
https://docs.clamav.net/#mailing-lists-and-chat
--===============5255304534469298450==--