• ClamAV vulnerability

    From bugz_ubuntu@21:4/110 to Ubuntu Users on Wednesday, January 08, 2020 12:10:05
    clamav vulnerability

    A security issue affects these releases of Ubuntu and its
    derivatives:

    * Ubuntu 19.10
    * Ubuntu 19.04
    * Ubuntu 18.04 LTS
    * Ubuntu 16.04 LTS

    Summary

    ClamAV could be made to crash if it opened a specially crafted
    file.

    Software Description

    * clamav - Anti-virus utility for Unix

    Details

    It was discovered that ClamAV incorrectly handled certain MIME
    messages. A remote attacker could possibly use this issue to cause
    ClamAV to crash, resulting in a denial of service.

    Update instructions

    The problem can be corrected by updating your system to the
    following package versions:

    Ubuntu 19.10
    clamav - 0.102.1+dfsg-0ubuntu0.19.10.2

    Ubuntu 19.04
    clamav - 0.102.1+dfsg-0ubuntu0.19.04.2

    Ubuntu 18.04 LTS
    clamav - 0.102.1+dfsg-0ubuntu0.18.04.2

    Ubuntu 16.04 LTS
    clamav - 0.102.1+dfsg-0ubuntu0.16.04.2

    To update your system, please follow these instructions:
    https://wiki.ubuntu.com/Security/Upgrades.

    This update uses a new upstream release, which includes additional
    bug fixes. In general, a standard system update will make all the
    necessary changes.

    References

    * CVE-2019-15961

    --- Mystic BBS v1.12 A43 (Linux/64)
    * Origin: BZ&BZ BBS (21:4/110)
  • From bugz_ubuntu@21:4/110 to Ubuntu Users on Thursday, January 23, 2020 16:10:02
    clamav vulnerability

    A security issue affects these releases of Ubuntu and its
    derivatives:

    * Ubuntu 14.04 ESM
    * Ubuntu 12.04 ESM

    Summary

    ClamAV could be made to crash if it opened a specially crafted
    file.

    Software Description

    * clamav - Anti-virus utility for Unix

    Details

    USN-4230-1 fixed a vulnerability in ClamAV. This update provides
    the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04
    ESM.

    Original advisory details:

    It was discovered that ClamAV incorrectly handled certain MIME
    messages. A remote attacker could possibly use this issue to cause
    ClamAV to crash, resulting in a denial of service.

    Update instructions

    The problem can be corrected by updating your system to the
    following package versions:

    Ubuntu 14.04 ESM
    clamav - 0.102.1+dfsg-0ubuntu0.14.04.1+esm1

    Ubuntu 12.04 ESM
    clamav - 0.102.1+dfsg-0ubuntu0.12.04.1

    To update your system, please follow these instructions:
    https://wiki.ubuntu.com/Security/Upgrades.

    This update uses a new upstream release, which includes additional
    bug fixes. In general, a standard system update will make all the
    necessary changes.

    References

    * USN-4230-1
    * CVE-2019-15961

    --- Mystic BBS v1.12 A43 (Linux/64)
    * Origin: BZ&BZ BBS (21:4/110)
  • From bugz_ubuntu@21:4/110 to Ubuntu Users on Tuesday, February 18, 2020 12:10:03
    clamav vulnerability

    A security issue affects these releases of Ubuntu and its
    derivatives:

    * Ubuntu 14.04 ESM
    * Ubuntu 12.04 ESM

    Summary

    ClamAV could be made to crash if it opened a specially crafted
    file.

    Software Description

    * clamav - Anti-virus utility for Unix

    Details

    USN-4280-1 fixed a vulnerability in ClamAV. This update provides
    the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04
    ESM.

    Original advisory details:

    It was discovered that ClamAV incorrectly handled memory when the
    Data-Loss-Prevention (DLP) feature was enabled. A remote attacker
    could possibly use this issue to cause ClamAV to crash, resulting
    in a denial of service.

    Update instructions

    The problem can be corrected by updating your system to the
    following package versions:

    Ubuntu 14.04 ESM
    clamav - 0.102.2+dfsg-0ubuntu0.14.04.1+esm1

    Ubuntu 12.04 ESM
    clamav - 0.102.2+dfsg-0ubuntu0.12.04.1

    To update your system, please follow these instructions:
    https://wiki.ubuntu.com/Security/Upgrades.

    This update uses a new upstream release, which includes additional
    bug fixes. In general, a standard system update will make all the
    necessary

    References

    * USN-4280-1
    * CVE-2020-3123

    --- Mystic BBS v1.12 A44 (Linux/64)
    * Origin: BZ&BZ BBS (21:4/110)
  • From bugz_ubuntu@21:4/110 to Ubuntu Users on Tuesday, February 18, 2020 12:10:03
    clamav vulnerability

    A security issue affects these releases of Ubuntu and its
    derivatives:

    * Ubuntu 19.10
    * Ubuntu 18.04 LTS
    * Ubuntu 16.04 LTS

    Summary

    ClamAV could be made to crash if it opened a specially crafted
    file.

    Software Description

    * clamav - Anti-virus utility for Unix

    Details

    It was discovered that ClamAV incorrectly handled memory when the
    Data-Loss-Prevention (DLP) feature was enabled. A remote attacker
    could possibly use this issue to cause ClamAV to crash, resulting
    in a denial of service.

    Update instructions

    The problem can be corrected by updating your system to the
    following package versions:

    Ubuntu 19.10
    clamav - 0.102.2+dfsg-0ubuntu0.19.10.1

    Ubuntu 18.04 LTS
    clamav - 0.102.2+dfsg-0ubuntu0.18.04.1

    Ubuntu 16.04 LTS
    clamav - 0.102.2+dfsg-0ubuntu0.16.04.1

    To update your system, please follow these instructions:
    https://wiki.ubuntu.com/Security/Upgrades.

    This update uses a new upstream release, which includes additional
    bug fixes. In general, a standard system update will make all the
    necessary

    References

    * CVE-2020-3123

    --- Mystic BBS v1.12 A44 (Linux/64)
    * Origin: BZ&BZ BBS (21:4/110)