Repository navigation
Update clamav to 0.99.3 #75
Copy link
Copy link
Closed
Description
Activity
This was done upstream in 26435b9 earlier, I've backported to 2017Q4 and it should be available within the next few hours.
Good to know. Did you saw the patch. This seem to be essential to prevent clamav crashings. A few german universities hat problems without this patch today (I was reading this on a german postfix mailinglist)
It was implemented in a slightly different way here:
https://github.com/NetBSD/pkgsrc/blob/trunk/security/clamav/patches/patch-libclamav_scanners.c
I've added this patch onto the version bump backport now, and will prep a 2017Q4 rebuild soon.
Thx a lot!
Backported into 2017Q4, the rebuilds are syncing now across the http mirrors.
Reacted by jfqd- added 2 commits that reference this issue
on Feb 19, 2018 - added a commit that references this issue
on Nov 10, 2018 - added 2 commits that reference this issue
on Aug 26, 2019 124 remaining items
- added a commit that references this issue
on Jun 2, 2026 - added a commit that references this issue
on Jun 12, 2026 - added a commit that references this issue
on Jun 24, 2026 - added 2 commits that reference this issue
on Sep 24, 2026
Metadata
Metadata
Assignees
Labels
No labels
Version 0.99.3 fixes seven CVEs. One of it can easily exploited by sending a special crafted PDF (CVE-2017-12376), which was seen in the wild.
There is also a patch needed for 0.99.3 which prevents crashing of clamav, see: http://lists.clamav.net/pipermail/clamav-users/2018-January/005687.html
Some people with large mailservers thought today must be friday the 13 :)