Bug 117648 (CVE-2005-2920) - VUL-0: CVE-2005-2920: clamav 0.87
Summary: VUL-0: CVE-2005-2920: clamav 0.87
Status: RESOLVED FIXED
Alias: CVE-2005-2920
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other All
: P5 - None : Major
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: CVE-2005-2920: CVSS v2 Base Score: 7....
Keywords:
Depends on:
Blocks:
 
Reported: 2005-09-17 20:22 UTC by Marcus Meissner
Modified: 2021-11-03 14:53 UTC (History)
3 users (show)

See Also:
Found By: Other
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2005-09-17 20:22:16 UTC
from clamav announcement: 
This version fixes vulnerabilities in handling of UPX and FSG compressed 
executables.  
>>>> this is security related. 
Support for PE files, Zip and Cabinet archives has been improved and other 
small bugfixes have been made.  
The new option "--on-outdated-execute" allows freshclam to run a command when 
system reports a new engine version.
Comment 1 Reinhard Max 2005-09-19 10:39:54 UTC
Updated packages have been submitted for 9.0, sles9, 9.2, 9.3, 10.0, and STABLE.

Mbuild packages are available under /work/built/mbuild/nitsch-max-1, and on
ftp://ftp.suse.com/pub/projects/clamav .

Matthias, can you please test them on the scan hosts?
Comment 2 Marcus Meissner 2005-09-19 12:28:08 UTC
SWAMPID: 2334 
Comment 3 Marcus Meissner 2005-09-19 13:44:14 UTC
patchinfos submitted. 
 
i only submitted for "clamav", we can leave the clamav-db alone, right? 
Comment 4 Reinhard Max 2005-09-19 13:59:38 UTC
Yes, those who use clamav seriously have to use freshclam to keep their virus
database up to date, and so they don't need the -db package at all, but
unfortunately the authors of ClamAV refused my suggestion to separate the
database from the source code distribution.
Comment 5 Matthias Boettger 2005-09-20 12:32:32 UTC
updated on our servers.
Comment 6 Marcus Meissner 2005-09-23 15:48:53 UTC
CAN-2005-2919 
CAN-2005-2920 
Comment 7 Marcus Meissner 2005-09-26 11:01:28 UTC
updates and advisory released. 
Comment 8 Thomas Biege 2009-10-13 21:29:32 UTC
CVE-2005-2920: CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)