Bug 495036 (CVE-2008-6680, CVE-2009-1241, CVE-2009-1270)
Summary: | clamav: security fixes in upstream 0.95 (CVE-2008-6680, CVE-2009-1270) | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Tomas Hoger <thoger> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED CURRENTRELEASE | QA Contact: | |
Severity: | high | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | redhat-bugzilla, rh-bugzilla, steve, vdanen |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2009-12-17 21:27:37 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Tomas Hoger
2009-04-09 09:04:46 UTC
For the sake of completeness... 0.95 also fixes following RAR check bypass, though RAR code is removed from Fedora build due to licensing resons. CVE-2009-1241: Unspecified vulnerability in ClamAV before 0.95 allows remote attackers to bypass detection of malware via a modified RAR archive. Upstream bug: https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1467 Upstream fix: svn diff -c 4977 http://svn.clamav.net/svn/clamav-devel/ Reference: http://blog.zoller.lu/2009/04/clamav-094-and-below-evasion-and-bypass.html Both CVE-2008-6680 and CVE-2009-1270 exist also in the oldest clamav version currently shipped - 0.93.3 in F9. 1963 (clamav): Build on target fedora-5-epel succeeded. 1965 (clamav): Build on target fedora-4-epel succeeded. Only Fedora 10 (0.94.2) is still affected by this issue; Fedora 11 has 0.95.2 and EPEL has 0.95.1. |