From 67f76a858f1ac826bd8a550d756d9ec6e340ed4f Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Sat, 27 Jan 2018 18:07:28 +0000 Subject: gentoo resync : 27.01.2018 --- metadata/glsa/glsa-201801-19.xml | 56 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 56 insertions(+) create mode 100644 metadata/glsa/glsa-201801-19.xml (limited to 'metadata/glsa/glsa-201801-19.xml') diff --git a/metadata/glsa/glsa-201801-19.xml b/metadata/glsa/glsa-201801-19.xml new file mode 100644 index 000000000000..42b4b79dfcef --- /dev/null +++ b/metadata/glsa/glsa-201801-19.xml @@ -0,0 +1,56 @@ + + + + ClamAV: Multiple vulnerabilities + Multiple vulnerabilities have been found in ClamAV, the worst of + which may allow execution of arbitrary code. + + clamav + 2018-01-26 + 2018-01-26 + 645794 + remote + + + 0.99.3 + 0.99.3 + + + +

ClamAV is a GPL virus scanner.

+
+ +

Multiple vulnerabilities have been discovered in ClamAV. Please review + the CVE identifiers referenced below for details. +

+
+ +

A remote attacker could cause ClamAV to scan a specially crafted file, + possibly resulting in execution of arbitrary code with the privileges of + the process or cause a Denial of Service condition. +

+
+ +

There is no known workaround at this time.

+
+ +

All ClamAV users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-antivirus/clamav-0.99.3" + + +
+ + CVE-2017-12374 + CVE-2017-12375 + CVE-2017-12376 + CVE-2017-12377 + CVE-2017-12378 + CVE-2017-12379 + CVE-2017-12380 + + whissi + whissi +
-- cgit v1.2.3