Oval Definition:oval:org.opensuse.security:def:90244
Revision Date:2019-11-25Version:1
Title:Security update for clamav (Moderate)
Description:

This update for clamav fixes the following issues:

Security issue fixed:

- CVE-2019-12625: Fixed a ZIP bomb issue by adding detection and heuristics for zips with overlapping files (bsc#1144504). - CVE-2019-12900: Fixed an out-of-bounds write in decompress.c with many selectors (bsc#1149458).

Non-security issues fixed:

- Added the --max-scantime clamscan option and MaxScanTime clamd configuration option (bsc#1144504). - Increased the startup timeout of clamd to 5 minutes to cater for the grown virus database as a workaround until clamd has learned to talk to systemd to extend the timeout as long as needed (bsc#1151839).
Family:unixClass:patch
Status:Reference(s):1144504
1149458
1151839
CVE-2019-12625
CVE-2019-12900
SUSE-SU-2019:3053-1
Platform(s):SUSE Linux Enterprise Desktop 15 SP1
SUSE Linux Enterprise High Performance Computing 15 SP1
SUSE Linux Enterprise Module for Basesystem 15 SP1
SUSE Linux Enterprise Server 15 SP1
SUSE Linux Enterprise Server for SAP Applications 15 SP1
SUSE Linux Enterprise Storage 6
SUSE Manager Proxy 4.0
SUSE Manager Server 4.0
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP1 is installed
  • AND Package Information
  • clamav-0.100.3-3.14.1 is installed
  • OR clamav-devel-0.100.3-3.14.1 is installed
  • OR libclamav7-0.100.3-3.14.1 is installed
  • OR libclammspack0-0.100.3-3.14.1 is installed
  • BACK