Bug 2170937 - CVE-2023-20032: possible remote code execution vulnerability in the HFS+ file parser of ClamAV
Summary: CVE-2023-20032: possible remote code execution vulnerability in the HFS+ file...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: clamav
Version: epel7
Hardware: Unspecified
OS: Unspecified
unspecified
urgent
Target Milestone: ---
Assignee: Sergio Basto
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2023-02-17 18:29 UTC by harald.svab
Modified: 2023-03-01 00:35 UTC (History)
4 users (show)

Fixed In Version: clamav-0.103.8-3.el8
Clone Of:
Environment:
Last Closed: 2023-03-01 00:35:03 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description harald.svab 2023-02-17 18:29:38 UTC
Description of problem:


CVE-2023-20032: Fixed a possible remote code execution vulnerability in the HFS+ file parser. The issue affects versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier. Thank you to Simon Scannell for reporting this issue.

CVE-2023-20052: Fixed a possible remote information leak vulnerability in the DMG file parser. The issue affects versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier. Thank you to Simon Scannell for reporting this issue.

Versions 0.103.8, 0.105.2 and 1.0.1 available for fix.

We would really need the new version for EPEL-7.

Comment 1 harald.svab 2023-02-17 18:32:22 UTC
sorry forgot to add a link to the source: https://blog.clamav.net/2023/02/clamav-01038-01052-and-101-patch.html

Comment 2 Ruben Püttmann 2023-02-21 08:46:26 UTC
Seems that fixed versionfor EPEL-8 and higher are available. What is with EPEL-7?

Comment 3 Fedora Update System 2023-02-24 16:44:46 UTC
FEDORA-EPEL-2023-5cb6798308 has been submitted as an update to Fedora EPEL 8. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-5cb6798308

Comment 4 Sergio Basto 2023-02-24 16:45:52 UTC
for EPEL-7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-466d8ae059

Comment 5 Fedora Update System 2023-03-01 00:35:03 UTC
FEDORA-EPEL-2023-5cb6798308 has been pushed to the Fedora EPEL 8 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.