SuSE: 2015:0298-1: important: clamav
Summary
clamav was updated to version 0.98.6 to fix four security issues.
These security issues have been fixed:
* CVE-2015-1462: ClamAV allowed remote attackers to have unspecified
impact via a crafted upx packer file, related to a heap out of
bounds condition (bnc#916214).
* CVE-2015-1463: ClamAV allowed remote attackers to cause a denial of
service (crash) via a crafted petite packer file, related to an
incorrect compiler optimization (bnc#916215).
* CVE-2014-9328: ClamAV allowed remote attackers to have unspecified
impact via a crafted upack packer file, related to a heap out of
bounds condition (bnc#915512).
* CVE-2015-1461: ClamAV allowed remote attackers to have unspecified
impact via a crafted (1) Yoda's crypter or (2) mew packer file,
related to a heap out of bounds condition (bnc#916217).
Security Issues:
* CVE-2015-1462
References
#915512 #916214 #916215 #916217
Cross- CVE-2014-9328 CVE-2015-1461 CVE-2015-1462
CVE-2015-1463
Affected Products:
SUSE Linux Enterprise Server 11 SP3 for VMware
SUSE Linux Enterprise Server 11 SP3
SUSE Linux Enterprise Server 11 SP2 LTSS
SUSE Linux Enterprise Server 11 SP1 LTSS
SUSE Linux Enterprise Server 10 SP4 LTSS
SUSE Linux Enterprise Desktop 11 SP3
https://www.suse.com/security/cve/CVE-2014-9328.html
https://www.suse.com/security/cve/CVE-2015-1461.html
https://www.suse.com/security/cve/CVE-2015-1462.html
https://www.suse.com/security/cve/CVE-2015-1463.html
https://bugzilla.suse.com/915512
https://bugzilla.suse.com/916214
https://bugzilla.suse.com/916215
https://bugzilla.suse.com/916217
https://scc.suse.com:443/patches/
https://scc.suse.com:443/patches/
https://scc.suse.com:443/patches/
https://scc.suse.com:443/pa...
Read the Full Advisory