SUSE Security Update: Security update for clamav
______________________________________________________________________________

Announcement ID:    SUSE-SU-2014:1571-1
Rating:             important
References:         #899395 #903489 #903719 #904207 #906077 #906770 
                    
Cross-References:   CVE-2013-6497 CVE-2014-9050
Affected Products:
                    SUSE Linux Enterprise Server 11 SP2 LTSS
                    SUSE Linux Enterprise Server 11 SP1 LTSS
______________________________________________________________________________

   An update that solves two vulnerabilities and has four
   fixes is now available. It includes one version update.

Description:


   clamav was updated to version 0.98.5 to fix five security issues:

       * Crash when scanning maliciously crafted yoda's crypter files
         (CVE-2013-6497).
       * Heap-based buffer overflow when scanning crypted PE files
         (CVE-2014-9050).
       * Fix heap corruption (CVE-2013-2020).
       * Fix overflow due to PDF key length computation (CVE-2013-2021).
       * Crash when using 'clamscan -a'.

   Several non-security issues have also been fixed, please refer to the
   package's change log for details.

   Security Issues:

       * CVE-2013-6497
         
       * CVE-2014-9050
         
       * CVE-2013-2021
         
       * CVE-2013-2020
         


Patch Instructions:

   To install this SUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Server 11 SP2 LTSS:

      zypper in -t patch slessp2-clamav-10015

   - SUSE Linux Enterprise Server 11 SP1 LTSS:

      zypper in -t patch slessp1-clamav-10014

   To bring your system up-to-date, use "zypper patch".


Package List:

   - SUSE Linux Enterprise Server 11 SP2 LTSS (i586 s390x x86_64) [New Version: 0.98.5]:

      clamav-0.98.5-0.5.1

   - SUSE Linux Enterprise Server 11 SP1 LTSS (i586 s390x x86_64) [New Version: 0.98.5]:

      clamav-0.98.5-0.5.1


References:

   https://www.suse.com/security/cve/CVE-2013-6497.html
   https://www.suse.com/security/cve/CVE-2014-9050.html
   https://bugzilla.suse.com/show_bug.cgi?id=899395
   https://bugzilla.suse.com/show_bug.cgi?id=903489
   https://bugzilla.suse.com/show_bug.cgi?id=903719
   https://bugzilla.suse.com/show_bug.cgi?id=904207
   https://bugzilla.suse.com/show_bug.cgi?id=906077
   https://bugzilla.suse.com/show_bug.cgi?id=906770
   https://scc.suse.com:443/patches/
   https://scc.suse.com:443/patches/

SuSE: 2014:1571-1: important: clamav

December 5, 2014
An update that solves two vulnerabilities and has four An update that solves two vulnerabilities and has four An update that solves two vulnerabilities and has four fixes is now av...

Summary

clamav was updated to version 0.98.5 to fix five security issues: * Crash when scanning maliciously crafted yoda's crypter files (CVE-2013-6497). * Heap-based buffer overflow when scanning crypted PE files (CVE-2014-9050). * Fix heap corruption (CVE-2013-2020). * Fix overflow due to PDF key length computation (CVE-2013-2021). * Crash when using 'clamscan -a'. Several non-security issues have also been fixed, please refer to the package's change log for details. Security Issues: * CVE-2013-6497 * CVE-2014-9050 * CVE-2013-2021 * CVE-2013-2020 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11 SP2 LTSS: zypper in -t patch slessp2-clamav-10015 - SUSE Linux Enterprise Server 11 SP1 LTSS: zypper ...

Read the Full Advisory

References

#899395 #903489 #903719 #904207 #906077 #906770

Cross- CVE-2013-6497 CVE-2014-9050

Affected Products:

SUSE Linux Enterprise Server 11 SP2 LTSS

SUSE Linux Enterprise Server 11 SP1 LTSS

https://www.suse.com/security/cve/CVE-2013-6497.html

https://www.suse.com/security/cve/CVE-2014-9050.html

https://bugzilla.suse.com/show_bug.cgi?id=899395

https://bugzilla.suse.com/show_bug.cgi?id=903489

https://bugzilla.suse.com/show_bug.cgi?id=903719

https://bugzilla.suse.com/show_bug.cgi?id=904207

https://bugzilla.suse.com/show_bug.cgi?id=906077

https://bugzilla.suse.com/show_bug.cgi?id=906770

https://scc.suse.com:443/patches/

https://scc.suse.com:443/patches/

Severity
Announcement ID: SUSE-SU-2014:1571-1
Rating: important

Related News