[ubuntu/artful-proposed] clamav 0.99.2+dfsg-6ubuntu2 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Tue Aug 15 20:40:13 UTC 2017


clamav (0.99.2+dfsg-6ubuntu2) artful; urgency=medium

  * SECURITY UPDATE: DoS via crafted e-mail message
    - debian/patches/CVE-2017-6418.patch: fix invalid read in
      libclamav/message.c.
    - CVE-2017-6418
  * SECURITY UPDATE: DoS via WWPack compression
    - debian/patches/CVE-2017-6420.patch: add bounds checks to
      libclamav/wwunpack.c.
    - debian/patches/CVE-2017-6420-2.patch: fix unit tests in
      libclamav/wwunpack.c, unit_tests/check_jsnorm.c.
    - CVE-2017-6420
  * debian/patches/fix_newer_zlib.patch: fix compatibility with zlib
    1.2.9 and newer (LP: #1692073).

Date: Tue, 15 Aug 2017 16:04:46 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/clamav/0.99.2+dfsg-6ubuntu2
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 15 Aug 2017 16:04:46 -0400
Source: clamav
Binary: clamav-base clamav-docs clamav libclamav-dev libclamav7 clamav-daemon clamdscan clamav-testfiles clamav-freshclam clamav-milter
Architecture: source
Version: 0.99.2+dfsg-6ubuntu2
Distribution: artful
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Description:
 clamav     - anti-virus utility for Unix - command-line interface
 clamav-base - anti-virus utility for Unix - base package
 clamav-daemon - anti-virus utility for Unix - scanner daemon
 clamav-docs - anti-virus utility for Unix - documentation
 clamav-freshclam - anti-virus utility for Unix - virus database update utility
 clamav-milter - anti-virus utility for Unix - sendmail integration
 clamav-testfiles - anti-virus utility for Unix - test files
 clamdscan  - anti-virus utility for Unix - scanner client
 libclamav-dev - anti-virus utility for Unix - development files
 libclamav7 - anti-virus utility for Unix - library
Launchpad-Bugs-Fixed: 1692073
Changes:
 clamav (0.99.2+dfsg-6ubuntu2) artful; urgency=medium
 .
   * SECURITY UPDATE: DoS via crafted e-mail message
     - debian/patches/CVE-2017-6418.patch: fix invalid read in
       libclamav/message.c.
     - CVE-2017-6418
   * SECURITY UPDATE: DoS via WWPack compression
     - debian/patches/CVE-2017-6420.patch: add bounds checks to
       libclamav/wwunpack.c.
     - debian/patches/CVE-2017-6420-2.patch: fix unit tests in
       libclamav/wwunpack.c, unit_tests/check_jsnorm.c.
     - CVE-2017-6420
   * debian/patches/fix_newer_zlib.patch: fix compatibility with zlib
     1.2.9 and newer (LP: #1692073).
Checksums-Sha1:
 e3a2d041bf1849eef5d042f601ec8f134072d43b 3144 clamav_0.99.2+dfsg-6ubuntu2.dsc
 2919597ff977e6e38b75f47747208285952d99c0 258620 clamav_0.99.2+dfsg-6ubuntu2.debian.tar.xz
 ea1d576a3f0e1a54363f233ef8be717c849f388e 8293 clamav_0.99.2+dfsg-6ubuntu2_source.buildinfo
Checksums-Sha256:
 4af338f00927e106ac67965efb0c384cef8182ccbb7165256ce62ce8408bcc69 3144 clamav_0.99.2+dfsg-6ubuntu2.dsc
 d854b20cab56a30d8672d62a49dbd987c9767c053e4c4219a43a8f1f39a017a7 258620 clamav_0.99.2+dfsg-6ubuntu2.debian.tar.xz
 831e02449a92d3db417f75f89ec17faa1e41c60b648799ce838b279e2c218761 8293 clamav_0.99.2+dfsg-6ubuntu2_source.buildinfo
Files:
 def6ccd6bc762fce1a12b5ab060306ab 3144 utils optional clamav_0.99.2+dfsg-6ubuntu2.dsc
 9b18d796758651e582cb3374df10eede 258620 utils optional clamav_0.99.2+dfsg-6ubuntu2.debian.tar.xz
 0c89e18f69b22ed6af6dc7d6a30b3d0a 8293 utils optional clamav_0.99.2+dfsg-6ubuntu2_source.buildinfo
Original-Maintainer: ClamAV Team <pkg-clamav-devel at lists.alioth.debian.org>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJZk1tRAAoJEGVp2FWnRL6T30oP/10afcbMUx63OCOFhzhPU1hw
BvOH7OMcohjTbtAl4YpSWYgi08fvIxdTw6dcuv88Y+zhvWGB2S17z9XtHsJ1dcFP
itOrd38HWpgdwF/gv3tYb3gdUCt4hCaV2qfhRls98NvF1AY+KYIsbyWwpPTVuMVY
B+A/tIMzgDbUkHffdlGtBMLaJAiwAicNnWnf2U3MEdNLFp5bu8peSI+qoR/5yGSq
XlAfdus18CTQmIBPksBNhR3UZbnhyBuPMNhuT1uWeLnuWiP6tjrzms2UJCdXLstE
RIN2rpCL9cNVwzNN0BIRWArPg4SMza4fYpmuWK2M1EtEK5JQAxyoeheTvQdg+zBR
gkINm4hauu9OAPCDgT6tXPI627RE/eMMIy2F8nfiqIz7CAyigSA05FEScEAvNssF
pi/h+2/P58vGwTvgnJzHRObZ7JaHnNwrM3LXTIDTuuLAzZQgLoD7Xuhm1PF7VbqH
OeXfe2PlCmtd9h8fVa+/unIJ8/NlJbfIqPWjPTGVmAiAhnOa3ZAn26mVGXzfpWGi
iqURZpgdY0VLufbNO1P2Gi5uZSeMwpiFc9yW3UFFS8Sd968tWbOfOxhKnFnC10Oh
kJqKOHmrfdy312jwvNvLGma5AEkIOkwnt9zkGvVSAMmEExzh6TXFdFxB1OpZzLl9
FoRL6/RQrJQSBKQf991d
=bzyx
-----END PGP SIGNATURE-----


More information about the Artful-changes mailing list