***UNCHECKED*** clamav remote code injection

Florian Gleixner <[email protected]> Sat, 27 Jan 2018 11:48:03 +0100
Newsgroups gmane.linux.suse.security
Message-ID <[email protected]>
This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--XGxS842U5Jn9mYBWeaVDxJ5HDNUmORY6U
Content-Type: multipart/mixed; boundary="PxL849gA9bdNIPwDDVpC4KIii4OQtrEq3";
 protected-headers="v1"
From: Florian Gleixner <[email protected]>
To: [email protected]
Message-ID: <[email protected]>
Subject: clamav remote code injection

--PxL849gA9bdNIPwDDVpC4KIii4OQtrEq3
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: quoted-printable

Hi,

there are reports from email service providers, that there are attempts
to exploit clamav using prepared pdf documents in mails. See (in german):=


https://www.heise.de/security/meldung/Jetzt-patchen-Angriffe-auf-Viren-Sc=
anner-ClamAV-3951801.html

I hope, the opensuse security team will release a update for clamav soon.=








--PxL849gA9bdNIPwDDVpC4KIii4OQtrEq3--

--XGxS842U5Jn9mYBWeaVDxJ5HDNUmORY6U
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iEYEARECAAYFAlpsWOMACgkQTEm7v/awm1xOnwCgzKKDMw+EJKmA9jReKq+K6YXW
l3YAoNItPTOvJMnX9PNEQCl1mafS0akX
=4WLb
-----END PGP SIGNATURE-----

--XGxS842U5Jn9mYBWeaVDxJ5HDNUmORY6U--
-- 
To unsubscribe, e-mail: [email protected]
To contact the owner, e-mail: [email protected]