SUSE-SU-2022:1644-1
Dashboard / Vulnerabilities / SUSE-SU-2022:1644-1
SUSE-SU-2022:1644-1
Summary: Security update for clamav
Details: This update for clamav fixes the following issues: - CVE-2022-20770: Fixed a possible infinite loop vulnerability in the CHM file parser (bsc#1199242). - CVE-2022-20796: Fixed a possible NULL-pointer dereference crash in the scan verdict cache check (bsc#1199246). - CVE-2022-20771: Fixed a possible infinite loop vulnerability in the TIFF file parser (bsc#1199244). - CVE-2022-20785: Fixed a possible memory leak in the HTML file parser / Javascript normalizer (bsc#1199245). - CVE-2022-20792: Fixed a possible multi-byte heap buffer overflow write vulnerability in the signature database load module (bsc#1199274).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20221644-1/, https://bugzilla.suse.com/1199242, https://bugzilla.suse.com/1199244, https://bugzilla.suse.com/1199245, https://bugzilla.suse.com/1199246, https://bugzilla.suse.com/1199274, https://www.suse.com/security/cve/CVE-2022-20770, https://www.suse.com/security/cve/CVE-2022-20771, https://www.suse.com/security/cve/CVE-2022-20785, https://www.suse.com/security/cve/CVE-2022-20792, https://www.suse.com/security/cve/CVE-2022-20796
Affected packages
Package
Name: clamav
Purl: pkg:rpm/suse/clamav&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
