Oval Definition:oval:org.opensuse.security:def:64918
Revision Date:2020-12-01Version:1
Title:Security update for clamav (Moderate)
Description:

This update for clamav fixes the following issues:

Security issue fixed:

- CVE-2019-12625: Fixed a ZIP bomb issue by adding detection and heuristics for zips with overlapping files (bsc#1144504). - CVE-2019-12900: Fixed an out-of-bounds write in decompress.c with many selectors (bsc#1149458).

Non-security issues fixed:

- Added the --max-scantime clamscan option and MaxScanTime clamd configuration option (bsc#1144504). - Increased the startup timeout of clamd to 5 minutes to cater for the grown virus database as a workaround until clamd has learned to talk to systemd to extend the timeout as long as needed (bsc#1151839).
Family:unixClass:patch
Status:Reference(s):1144504
1149458
1151839
1171696
1172356
1174386
1174543
1174641
1174863
1175370
1175441
1176494
1178630
1178703
CVE-2019-12625
CVE-2019-12900
CVE-2020-14364
CVE-2020-15863
CVE-2020-16013
CVE-2020-16016
CVE-2020-16017
CVE-2020-16092
CVE-2020-1945
CVE-2020-24352
openSUSE-SU-2020:1022-1
openSUSE-SU-2020:1664-1
SUSE-SU-2019:3053-1
SUSE-SU-2020:2158-1
Platform(s):openSUSE Leap 15.2
SUSE Linux Enterprise Module for Basesystem 15 SP1
Product(s):
Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • ant-1.10.7-lp152.2.3 is installed
  • OR ant-antlr-1.10.7-lp152.2.3 is installed
  • OR ant-apache-bcel-1.10.7-lp152.2.3 is installed
  • OR ant-apache-bsf-1.10.7-lp152.2.3 is installed
  • OR ant-apache-log4j-1.10.7-lp152.2.3 is installed
  • OR ant-apache-oro-1.10.7-lp152.2.3 is installed
  • OR ant-apache-regexp-1.10.7-lp152.2.3 is installed
  • OR ant-apache-resolver-1.10.7-lp152.2.3 is installed
  • OR ant-apache-xalan2-1.10.7-lp152.2.3 is installed
  • OR ant-commons-logging-1.10.7-lp152.2.3 is installed
  • OR ant-commons-net-1.10.7-lp152.2.3 is installed
  • OR ant-imageio-1.10.7-lp152.2.3 is installed
  • OR ant-javamail-1.10.7-lp152.2.3 is installed
  • OR ant-jdepend-1.10.7-lp152.2.3 is installed
  • OR ant-jmf-1.10.7-lp152.2.3 is installed
  • OR ant-jsch-1.10.7-lp152.2.3 is installed
  • OR ant-junit-1.10.7-lp152.2.3 is installed
  • OR ant-junit5-1.10.7-lp152.2.3 is installed
  • OR ant-manual-1.10.7-lp152.2.3 is installed
  • OR ant-scripts-1.10.7-lp152.2.3 is installed
  • OR ant-swing-1.10.7-lp152.2.3 is installed
  • OR ant-testutil-1.10.7-lp152.2.3 is installed
  • OR ant-xz-1.10.7-lp152.2.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP1 is installed
  • AND Package Information
  • clamav-0.100.3-3.14 is installed
  • OR clamav-devel-0.100.3-3.14 is installed
  • OR libclamav7-0.100.3-3.14 is installed
  • OR libclammspack0-0.100.3-3.14 is installed
  • BACK