MGASA-2015-0190
Dashboard / Vulnerabilities / MGASA-2015-0190
MGASA-2015-0190
Summary: Updated clamav packages fix security vulnerabilities
Details: This updates fixes the following security issues: Fix infinite loop condition on crafted y0da cryptor file. Identified and patch suggested by Sebastian Andrzej Siewior. CVE-2015-2221 Fix crash on crafted petite packed file. Reported and patch supplied by Sebastian Andrzej Siewior. CVE-2015-2222. Fix an infinite loop condition on a crafted "xz" archive file. This was reported by Dimitri Kirchner and Goulven Guiheux.CVE-2015-2668 Apply upstream patch for possible heap overflow in Henry Spencer's regex library. CVE-2015-2305 Fix crash in upx decoder with crafted file. Discovered and patch supplied by Sebastian Andrzej Siewior. CVE-2015-2170
References: https://advisories.mageia.org/MGASA-2015-0190.html, https://bugs.mageia.org/show_bug.cgi?id=15792, http://openwall.com/lists/oss-security/2015/05/03/1, http://openwall.com/lists/oss-security/2015/05/03/2, http://openwall.com/lists/oss-security/2015/05/03/3, http://openwall.com/lists/oss-security/2015/05/03/4, http://openwall.com/lists/oss-security/2015/05/03/5
Affected packages
Package
Name: clamav
Purl: pkg:rpm/mageia/clamav?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
