Re: ClamAV 1.5.0 now available!
"Val Snyder \(micasnyd\) via clamav-devel" <[email protected]> Fri, 10 Oct 2025 20:07:48 +0000
| Newsgroups | gmane.comp.security.virus.clamav.devel,gmane.comp.security.virus.clamav.win32 |
|---|---|
| Message-ID | <CH3PR11MB8750B811F1A1020167155222C6EFA@CH3PR11MB8750.namprd11.prod.outlook.com> |
Hi everyone, Shortly after the 1.5.0 release, we learned of a performance issue when sca= nning some Windows executables, as well as a bug in the ZIP parser relating= to the alert-exceeds-max feature. While they are not security issues, I fe= el that it is worth it to prioritize making a 1.5.1 patch version as quickl= y as possible. If you were looking to adopt ClamAV 1.5.0 and wish to wait for it, we shoul= d have a 1.5.1 version out in the coming week or two. Respectfully, Val Valerie Snyder (she/they) ClamAV Development Talos Cisco Systems, Inc. ________________________________ From: clamav-devel <[email protected]> on behalf of Val= Snyder (micasnyd) via clamav-devel <[email protected]> Sent: Tuesday, October 7, 2025 10:26 AM To: ClamAV Announcements ML <[email protected]> Cc: Val Snyder (micasnyd) <[email protected]>; ClamAV users ML <clamav-use= [email protected]>; ClamAV Development <[email protected]> Subject: [Clamav-devel] ClamAV 1.5.0 now available! Read this online at https://blog.clamav.net/2025/10/clamav-150-released.html The ClamAV 1.5.0 is now available. You may find the source code and install= ers for this release at clamav.net/downloads<https://www.clamav.net/downloa= ds> or on the ClamAV GitHub release page<https://github.com/Cisco-Talos/cla= mav/releases/tag/clamav-1.5.0>. IMPORTANT: A major feature of the 1.5 release is a FIPS-mode compatible met= hod for verifying the authenticity of CVD signature database archives and C= DIFF signature database patch files. This feature relies on =93.cvd.sign=94= signature files for the daily, main, and bytecode databases. The Freshclam= with 1.5.0 will download these files as will the latest version of CVDUpda= te. When they are not present, ClamAV will fall back to using the legacy MD= 5-based RSA signature check. Tip: If you are downloading the source from the GitHub release page, the pa= ckage labeled "clamav-1.5.0.tar.gz" does not require an internet connection= to build. All dependencies are included in this package. However, if you d= ownload the ZIP or TAR.GZ generated by GitHub, located at the very bottom, = then an internet connection will be required during the build to download a= dditional Rust dependencies. ClamAV 1.5.0 includes the following improvements and changes: Major changes * Added checks to determine if an OLE2-based Microsoft Office document is enc= rypted. GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1295> * Added the ability to record URIs found in HTML if the generate-JSON-metadat= a feature is enabled. Also adds an option to disable this in case you want = the JSON metadata feature but do not want to record HTML URIs. The ClamScan= command-line option is --json-store-html-uris=3Dno. The clamd.conf config = option is JsonStoreHTMLURIs no. The libclamav general scan option is CL_SCA= N_GENERAL_STORE_HTML_URIS GitHub pull request #1<https://github.com/Cisco-Talos/clamav/pull/1281> GitHub pull request #2<https://github.com/Cisco-Talos/clamav/pull/1482> GitHub pull request #3<https://github.com/Cisco-Talos/clamav/pull/1514> * Added the ability to record URIs found in PDFs if the generate-JSON-metadat= a feature is enabled. Also adds an option to disable this in case you want = the JSON metadata feature but do not want to record PDF URIs. The ClamScan = command-line option is --json-store-pdf-uris=3Dno. The clamd.conf config op= tion is JsonStorePDFURIs no. The libclamav general scan option is CL_SCAN_G= ENERAL_STORE_PDF_URIS GitHub pull request #1<https://github.com/Cisco-Talos/clamav/pull/1482> GitHub pull request #2<https://github.com/Cisco-Talos/clamav/pull/1514> GitHub pull request #3<https://github.com/Cisco-Talos/clamav/pull/1559> GitHub pull request #4<https://github.com/Cisco-Talos/clamav/pull/1572> * Added regex support for the clamd.conf OnAccessExcludePath config option. T= his change courtesy of GitHub user b1tg. GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1314> * Added CVD signing/verification with external .sign files. Freshclam will now attempt to download external signature files to accompan= y existing .cvd databases and .cdiff patch files. Sigtool now has commands = to sign and verify using the external signatures. ClamAV now installs a 'certs' directory in the app config directory (e.g., = <prefix>/etc/certs). The install path is configurable. The CMake option to = configure the CVD certs directory is -D CVD_CERTS_DIRECTORY=3DPATH New options to set an alternative CVD certs directory: Added two new APIs to the public clamav.h header: cl_error_t cl_cvdverify_ex( const char *file, const char *certs_directory, uint32_t dboptions); cl_error_t cl_cvdunpack_ex( const char *file, const char *dir, const char *certs_directory, uint32_t dboptions); The original cl_cvdverify and cl_cvdunpack are deprecated. Added a cl_engine_field enum option CL_ENGINE_CVDCERTSDIR. You may set this= option with cl_engine_set_str and get it with cl_engine_get_str, to overri= de the compiled in default CVD certs directory. Thank you to Mark Carey at SAP for inspiring work on this feature with an i= nitial proof of concept for external-signature FIPS compliant CVD signing. GitHub pull request #1<https://github.com/Cisco-Talos/clamav/pull/1417> GitHub pull request #2<https://github.com/Cisco-Talos/clamav/pull/1478> GitHub pull request #3<https://github.com/Cisco-Talos/clamav/pull/1489> GitHub pull request #4<https://github.com/Cisco-Talos/clamav/pull/1491> * The command-line option for Freshclam, ClamD, ClamScan, and Sigtoo= l is --cvdcertsdir PATH * The environment variable for Freshclam, ClamD, ClamScan, and Sigto= ol is CVD_CERTS_DIR * The config option for Freshclam and ClamD is CVDCertsDirectory PATH * Freshclam, ClamD, ClamScan, and Sigtool: Added an option to enable FIPS-lik= e limits disabling MD5 and SHA1 from being used for verifying digital signa= tures or for being used to trust a file when checking for false positives (= FPs). For freshclam.conf and clamd.conf set this config option: FIPSCryptoHashLimits yes For clamscan and sigtool use this command-line option: --fips-limits For libclamav: Enable FIPS-limits for a ClamAV engine like this: cl_engine_set_num(engine, CL_ENGINE_FIPS_LIMITS, 1); ClamAV will also attempt to detect if FIPS-mode is enabled. If so, it will = automatically enable the FIPS-limits feature. This change mitigates safety concerns over the use of MD5 and SHA1 algorith= ms to trust files and is required to enable ClamAV to operate legitimately = in FIPS-mode enabled environments. Note: ClamAV may still calculate MD5 or SHA1 hashes as needed for detection= purposes or for informational purposes in FIPS-enabled environments and wh= en the FIPS-limits option is enabled. GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532> * Upgraded the clean-file scan cache to use SHA2-256 (prior versions use MD5)= . The clean-file cache algorithm is not configurable. This change resolves safety concerns over the use of MD5 to trust files and= is required to enable ClamAV to operate legitimately in FIPS-mode enabled = environments. GitHub pull request #1<https://github.com/Cisco-Talos/clamav/pull/1532> GitHub pull request #2<https://github.com/Cisco-Talos/clamav/pull/1560> * ClamD: Added an option to disable select administrative commands including = SHUTDOWN, RELOAD, STATS and VERSION. The new clamd.conf options are: EnableShutdownCommand yes EnableReloadCommand yes EnableStatsCommand yes EnableVersionCommand yes This change courtesy of GitHub user ChaoticByte. GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1502> * libclamav: Added extended hashing functions with a "flags" parameter that a= llows the caller to choose if they want to bypass FIPS hash algorithm limit= s: cl_error_t cl_hash_data_ex( const char *alg, const uint8_t *data, size_t data_len, uint8_t **hash, size_t *hash_len, uint32_t flags); cl_error_t cl_hash_init_ex( const char *alg, uint32_t flags, cl_hash_ctx_t **ctx_out); cl_error_t cl_update_hash_ex( cl_hash_ctx_t *ctx, const uint8_t *data, size_t length); cl_error_t cl_finish_hash_ex( cl_hash_ctx_t *ctx, uint8_t **hash, size_t *hash_len, uint32_t flags); void cl_hash_destroy(void *ctx); cl_error_t cl_hash_file_fd_ex( const char *alg, int fd, size_t offset, size_t length, uint8_t **hash, size_t *hash_len, uint32_t flags); GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532> * ClamScan: Improved the precision of the bytes-scanned and bytes-read counte= rs. The ClamScan scan summary will now report exact counts in "GiB", "MiB",= "KiB", or "B" as appropriate. Previously, it always reported "MB". GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532> * ClamScan: Add hash & file-type in/out CLI options: We will not be adding this for ClamDScan, as we do not have a mechanism in = the ClamD socket API to receive scan options or a way for ClamD to include = scan metadata in the response. GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532> * --hash-hint: The file hash so that libclamav does not need to calc= ulate it. The type of hash must match the --hash-alg. * --log-hash: Print the file hash after each file scanned. The type = of hash printed will match the --hash-alg. * --hash-alg: The hashing algorithm used for either --hash-hint or -= -log-hash. Supported algorithms are "md5", "sha1", "sha2-256". If not speci= fied, the default is "sha2-256". * --file-type-hint: The file type hint so that libclamav can optimiz= e scanning (e.g., "pe", "elf", "zip", etc.). You may also use ClamAV type n= ames such as "CL_TYPE_PE". ClamAV will ignore the hint if it is not familia= r with the specified type. See also: https://docs.clamav.net/appendix/FileT= ypes.html#file-types * --log-file-type: Print the file type after each file scanned. * libclamav: Added new scan functions that provide additional functionality: cl_error_t cl_scanfile_ex( const char *filename, cl_verdict_t *verdict_out, const char **last_alert_out, uint64_t *scanned_out, const struct cl_engine *engine, struct cl_scan_options *scanoptions, void *context, const char *hash_hint, char **hash_out, const char *hash_alg, const char *file_type_hint, char **file_type_out); cl_error_t cl_scandesc_ex( int desc, const char *filename, cl_verdict_t *verdict_out, const char **last_alert_out, uint64_t *scanned_out, const struct cl_engine *engine, struct cl_scan_options *scanoptions, void *context, const char *hash_hint, char **hash_out, const char *hash_alg, const char *file_type_hint, char **file_type_out); cl_error_t cl_scanmap_ex( cl_fmap_t *map, const char *filename, cl_verdict_t *verdict_out, const char **last_alert_out, uint64_t *scanned_out, const struct cl_engine *engine, struct cl_scan_options *scanoptions, void *context, const char *hash_hint, char **hash_out, const char *hash_alg, const char *file_type_hint, char **file_type_out); The older cl_scan*() functions are now deprecated and may be removed in a f= uture release. See clamav.h for more details. GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532> * libclamav: Added a new engine option to toggle temp directory recursion. Temp directory recursion is the idea that each object scanned in ClamAV's r= ecursive extract/scan process will get a new temp subdirectory, mimicking t= he nesting structure of the file. Temp directory recursion was introduced in ClamAV 0.103 and is enabled when= ever --leave-temps / LeaveTemporaryFiles is enabled. In ClamAV 1.5, an application linking to libclamav can separately enable te= mp directory recursion if they wish. For ClamScan and ClamD, it will remain= tied to --leave-temps / LeaveTemporaryFiles options. The new temp directory recursion option can be enabled with: cl_engine_set_num(engine, CL_ENGINE_TMPDIR_RECURSION, 1); GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532> * libclamav: Added a class of scan callback functions that can be added with = the following API function: void cl_engine_set_scan_callback(struct cl_engine *engine, clcb_scan callba= ck, cl_scan_callback_t location); The scan callback location may be configured using the following five value= s: Each callback may alter scan behavior using the following return codes: Each callback is given a pointer to the current scan layer from which they = can get previous layers, can get the layer's fmap, and then various attribu= tes of the layer and of the fmap. To make this possible, there are new APIs= to query scan-layer details and fmap details: cl_error_t cl_fmap_set_name(cl_fmap_t *map, const char *name); cl_error_t cl_fmap_get_name(cl_fmap_t *map, const char **name_out); cl_error_t cl_fmap_set_path(cl_fmap_t *map, const char *path); cl_error_t cl_fmap_get_path(cl_fmap_t *map, const char **path_out, size_t= *offset_out, size_t *len_out); cl_error_t cl_fmap_get_fd(const cl_fmap_t *map, int *fd_out, size_t *offs= et_out, size_t *len_out); cl_error_t cl_fmap_get_size(const cl_fmap_t *map, size_t *size_out); cl_error_t cl_fmap_set_hash(const cl_fmap_t *map, const char *hash_alg, c= har hash); cl_error_t cl_fmap_have_hash(const cl_fmap_t *map, const char *hash_alg, = bool *have_hash_out); cl_error_t cl_fmap_will_need_hash_later(const cl_fmap_t *map, const char = *hash_alg); cl_error_t cl_fmap_get_hash(const cl_fmap_t *map, const char *hash_alg, c= har **hash_out); cl_error_t cl_fmap_get_data(const cl_fmap_t *map, size_t offset, size_t l= en, const uint8_t **data_out, size_t *data_len_out); cl_error_t cl_scan_layer_get_fmap(cl_scan_layer_t *layer, cl_fmap_t **fma= p_out); cl_error_t cl_scan_layer_get_parent_layer(cl_scan_layer_t *layer, cl_scan= _layer_t **parent_layer_out); cl_error_t cl_scan_layer_get_type(cl_scan_layer_t *layer, const char **ty= pe_out); cl_error_t cl_scan_layer_get_recursion_level(cl_scan_layer_t *layer, uint= 32_t *recursion_level_out); cl_error_t cl_scan_layer_get_object_id(cl_scan_layer_t *layer, uint64_t *= object_id_out); cl_error_t cl_scan_layer_get_last_alert(cl_scan_layer_t *layer, const cha= r **alert_name_out); cl_error_t cl_scan_layer_get_attributes(cl_scan_layer_t *layer, uint32_t = *attributes_out); This deprecates, but does not immediately remove, the existing scan callbac= ks: void cl_engine_set_clcb_pre_cache(struct cl_engine *engine, clcb_pre_cach= e callback); void cl_engine_set_clcb_file_inspection(struct cl_engine *engine, clcb_fi= le_inspection callback); void cl_engine_set_clcb_pre_scan(struct cl_engine *engine, clcb_pre_scan = callback); void cl_engine_set_clcb_post_scan(struct cl_engine *engine, clcb_post_sca= n callback); void cl_engine_set_clcb_virus_found(struct cl_engine *engine, clcb_virus_= found callback); void cl_engine_set_clcb_hash(struct cl_engine *engine, clcb_hash callback= ); There is an interactive test program to demonstrate the new callbacks. See:= examples/ex_scan_callbacks.c GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532> * CL_SCAN_CALLBACK_PRE_HASH: Occurs just after basic file-type detec= tion and before any hashes have been calculated either for the cache or the= gen-json metadata. * CL_SCAN_CALLBACK_PRE_SCAN: Occurs before parser modules run and be= fore pattern matching. * CL_SCAN_CALLBACK_POST_SCAN: Occurs after pattern matching and afte= r running parser modules. A.k.a. the scan is complete for this layer. * CL_SCAN_CALLBACK_ALERT: Occurs each time an alert (detection) woul= d be triggered during a scan. * CL_SCAN_CALLBACK_FILE_TYPE: Occurs each time the file type determi= nation is refined. This may happen more than once per layer. * CL_BREAK: Scan aborted by callback. The rest of the scan is skipped. This d= oes not mark the file as clean or infected, it just skips the rest of the s= can. * CL_SUCCESS / CL_CLEAN: File scan will continue. For CL_SCAN_CALLBACK_ALERT: This means you want to ignore this specific ale= rt and keep scanning. This is different than CL_VERIFIED because it does not affect prior or futu= re alerts. Return CL_VERIFIED instead if you want to remove prior alerts fo= r this layer and skip the rest of the scan for this layer. * CL_VIRUS: This means you do not trust the file. A new alert will be added. For CL_SCAN_CALLBACK_ALERT: This means you agree with the alert and no extr= a alert is needed. * CL_VERIFIED: Layer explicitly trusted by the callback and previous alerts r= emoved for THIS layer. You might want to do this if you trust the hash or v= erified a digital signature. The rest of the scan will be skipped for THIS = layer. For contained files, this does NOT mean that the parent or adjacent = layers are trusted. * Signature names that start with "Weak." will no longer alert. Instead, they= will be tracked internally and can be found in scan metadata JSON. This is= a step towards enabling alerting signatures to depend on prior Weak indica= tor matches in the current layer or in child layers. GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532> * For the "Generate Metadata JSON" feature: GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532> * The "Viruses" array of alert names has been replaced by two new arrays that= include additional details beyond just signature name: * "Indicators" records three types of indicators: * Strong indicators are for traditional alerting signature mat= ches and will halt the scan, except in all-match mode. * Potentially Unwanted indicators will only cause an alert at = the end of the scan unless a Strong indicator is found. They are treated th= e same as Strong indicators in all-match mode. * Weak indicators do not alert and will be leveraged in a futu= re version as a condition for logical signature matches. * "Alerts" records only alerting indicators. Events that trust a = file, such as false positive signatures, will remove affected indicators, a= nd mark them as "Ignored" in the "Indicators" array. * Add new option to calculate and record additional hash types when the "gene= rate metadata JSON" feature is enabled: * libclamav option: CL_SCAN_GENERAL_STORE_EXTRA_HASHES * ClamScan option: --json-store-extra-hashes (default off) * clamd.conf option: JsonStoreExtraHashes (default 'no') * The file hash is now stored as "sha2-256" instead of "FileMD5". If you enab= le the "extra hashes" option, then it will also record "md5" and "sha1". * Each object scanned now has a unique "Object ID". * Sigtool: Renamed the sigtool option --sha256 to --sha2-256. The original op= tion is still functional but is deprecated. GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532> Other improvements * Set a limit on the max-recursion config option. Users will no longer be abl= e to set max-recursion higher than 100. This change prevents errors on star= t up or crashes if encountering a file with that many layers of recursion. GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1264> * Build system: CMake improvements to support compiling for the AIX platform.= This change is courtesy of GitHub user KamathForAIX. GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1387> * Improve support for extracting malformed zip archives. This change is court= esy of Frederick Sell. GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1460> * Windows: Code quality improvement for the ClamScan and ClamDScan --move and= --remove options. This change is courtesy of Maxim Suhanov. GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1470> * Added file type recognition for an initial set of AI model file types. The file type is accessible to applications using libclamav via the scan ca= llback functions and as an optional output parameter to the scan functions:= cl_scanfile_ex(), cl_scanmap_ex(), and cl_scandesc_ex(). When scanning these files, type will now show "CL_TYPE_AI_MODEL" instead of= "CL_TYPE_BINARY_DATA". GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1476> * Added support for inline comments in ClamAV configuration files. This chang= e is courtesy of GitHub user userwiths. GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1308> * Disabled the MyDoom hardcoded/heuristic detection because of false positive= s. GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1495> * Sigtool: Added support for creating .cdiff and .script patch files for CVDs= that have underscores in the CVD name. Also improved support for relative = paths with the --diff command. GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1541> * Windows: Improved support for file names with UTF-8 characters not found in= the ANSI or OEM code pages when printing scan results or showing activity = in the ClamDTOP monitoring utility. Fixed a bug with opening files with suc= h names with the Sigtool utility. GitHub pull request #1<https://github.com/Cisco-Talos/clamav/pull/1461> GitHub pull request #2<https://github.com/Cisco-Talos/clamav/pull/1537> * Improved the code quality of the ZIP module. Added inline documentation. GitHub pull request #1<https://github.com/Cisco-Talos/clamav/pull/1548> GitHub pull request #2<https://github.com/Cisco-Talos/clamav/pull/1552> * Always run scan callbacks for embedded files. Embedded files are found with= in other files through signature matches instead of by parsing. They will n= ow be processed the same way and then they can trigger application callback= s (e.g., "pre-scan", "post-scan", etc.). A consequence of this change is that each embedded file will be pattern- ma= tched just like any other extracted file. To minimize excessive pattern mat= ching, file header validation checks were added for ZIP, ARJ, and CAB. Also= fixed a bug with embedded PE file scanning to reduce unnecessary matching. This change will impact scans with both the "leave-temps" feature and the "= force-to-disk" feature enabled, resulting in additional temporary files. GitHub pull request #1<https://github.com/Cisco-Talos/clamav/pull/1532> GitHub pull request #2<https://github.com/Cisco-Talos/clamav/pull/1571> * Added DevContainer templates to the ClamAV Git repository in order to make = it easier to set up AlmaLinux or Debian development environments. GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1462> * Removed the "Heuristics.XZ.DicSizeLimit" alert because of potential uninten= ded alerts based on system state. GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1573> * Improved support for compiling on Solaris. This fix courtesy of Andrew Watkins. GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1569> * Improved support for compiling on GNU/Hurd. This fix courtesy of Pino Toscano. GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1569> * Improved support for linking with the NCurses library dependency when libti= nfo is built as a separate library. GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1356> Bug fixes * Reduced email multipart message parser complexity. GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1347> * Fixed possible undefined behavior in inflate64 module. The inflate64 module= is a modified version of the zlib library, taken from version 1.2.3 with s= ome customization and with some cherry-picked fixes. This adds one addition= al fix from zlib 1.2.9. Thank you to TITAN Team for reporting this issue. GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1469> * Fixed a bug in ClamD that broke reporting of memory usage on Linux. The STA= TS command can be used to monitor ClamD directly or through ClamDTOP. The m= emory stats feature does not work on all platforms (e.g., Windows). GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1465> * Windows: Fixed a build issue when the same library dependency is found in t= wo different locations. GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1453> * Fixed an infinite loop when scanning some email files in debug-mode. This f= ix is courtesy of Yoann Lecuyer. GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1445> * Fixed a stack buffer overflow bug in the phishing signature load process. T= his fix is courtesy of GitHub user Shivam7-1. GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1486> * Fixed a race condition in the Freshclam feature tests. This fix is courtesy= of GitHub user rma-x. GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1513> * Windows: Fixed a 5-byte heap buffer overread in the Windows unit tests. Thi= s fix is courtesy of GitHub user Sophie0x2E. GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1542> * Fix double-extraction of OOXML-based office documents. GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532> * ClamBC: Fixed crashes on startup. GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532> * Fixed an assortment of issues found with Coverity static analysis. GitHub pull request #1<https://github.com/Cisco-Talos/clamav/pull/1574> GitHub pull request #2<https://github.com/Cisco-Talos/clamav/pull/1582> * Fixed libclamav unit test, ClamD, and ClamDScan Valgrind test failures affe= cting some platforms. GitHub pull request #1<https://github.com/Cisco-Talos/clamav/pull/1554> GitHub pull request #2<https://github.com/Cisco-Talos/clamav/pull/1570> * Fixed crash in the Sigtool program when using the --html-normalize option. GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1556> * Fixed some potential NULL-pointer dereference issues if memory allocations = fail. Fix courtesy of GitHub user JiangJias. GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1581> Acknowledgments Special thanks to the following people for code contributions and bug repor= ts: * Andrew Watkins * b1tg * ChaoticByte * Frederick Sell * KamathForAIX * Mark Carey at SAP * Maxim Suhanov * Pino Toscano * rma-x * Shivam7-1 * Sophie0x2E * TITAN Team * userwiths * Yoann Lecuyer Valerie Snyder (she/they) ClamAV Development Talos Cisco Systems, Inc. _______________________________________________ clamav-devel mailing list [email protected] https://lists.clamav.net/mailman/listinfo/clamav-devel Please submit your patches to our Github: https://github.com/Cisco-Talos/cl= amav-devel/pulls Help us build a comprehensive ClamAV guide: https://github.com/vrtadmin/clamav-faq http://www.clamav.net/contact.html#ml _______________________________________________ clamav-devel mailing list [email protected] https://lists.clamav.net/mailman/listinfo/clamav-devel Please submit your patches to our Github: https://github.com/Cisco-Talos/cl= amav-devel/pulls Help us build a comprehensive ClamAV guide: https://github.com/vrtadmin/clamav-faq http://www.clamav.net/contact.html#ml