Debian 9859 Published by

Updated ClamAV packages has been released for Debian GNU/Linux 8 LTS



Package : clamav
Version : 0.101.4+dfsg-0+deb8u1
CVE ID : CVE-2019-12625 CVE-2019-12900
Debian Bug : 34359

It was discovered that clamav, the open source antivirus engine, is affected by
the following security vulnerabilities:

CVE-2019-12625

Denial of Service (DoS) vulnerability, resulting from excessively long scan
times caused by non-recursive zip bombs. Among others, this issue was
mitigated by introducing a scan time limit.

CVE-2019-12900

Out-of-bounds write in ClamAV's NSIS bzip2 library when attempting
decompression in cases where the number of selectors exceeded the max limit
set by the library.

This update triggers a transition from libclamav7 to libclama9. As a result,
several other packages will be recompiled against the fixed package after the
release of this update: dansguardian, havp, python-pyclamav, c-icap-modules.

For Debian 8 "Jessie", these problems have been fixed in version
0.101.4+dfsg-0+deb8u1.

We recommend that you upgrade your clamav packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
  ClamAV Security Update for Debian 8 LTS