Skip to content

Update clamav to 0.99.3 #75

Description

@jfqd

Version 0.99.3 fixes seven CVEs. One of it can easily exploited by sending a special crafted PDF (CVE-2017-12376), which was seen in the wild.

There is also a patch needed for 0.99.3 which prevents crashing of clamav, see: http://lists.clamav.net/pipermail/clamav-users/2018-January/005687.html

Some people with large mailservers thought today must be friday the 13 :)

Activity

  1. self-assigned this
    on Jan 26, 2018
  2. jperkin commented on Jan 26, 2018

    @jperkin
    Collaborator

    This was done upstream in 26435b9 earlier, I've backported to 2017Q4 and it should be available within the next few hours.

  3. jfqd commented on Jan 26, 2018

    @jfqd
    Author

    Good to know. Did you saw the patch. This seem to be essential to prevent clamav crashings. A few german universities hat problems without this patch today (I was reading this on a german postfix mailinglist)

  4. mamash commented on Feb 1, 2018

    @mamash

    It was implemented in a slightly different way here:

    https://github.com/NetBSD/pkgsrc/blob/trunk/security/clamav/patches/patch-libclamav_scanners.c

    I've added this patch onto the version bump backport now, and will prep a 2017Q4 rebuild soon.

  5. jfqd commented on Feb 1, 2018

    @jfqd
    Author

    Thx a lot!

  6. mamash commented on Feb 1, 2018

    @mamash

    Backported into 2017Q4, the rebuilds are syncing now across the http mirrors.

  7. added a commit that references this issue on Aug 20, 2018
  8. added a commit that references this issue on Sep 24, 2018
  9. added a commit that references this issue on Nov 10, 2018
  10. added 2 commits that reference this issue on Aug 26, 2019
    e5cafae
    0aff30f
  11. added a commit that references this issue on Oct 6, 2019
  12. 124 remaining items

  13. added a commit that references this issue on Jun 12, 2026
  14. added a commit that references this issue on Jun 24, 2026
  15. added a commit that references this issue on Jul 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions