Bugzilla – Bug 915512
VUL-0: CVE-2014-9328: clamav: heap out of bounds condition with crafted upack packer files
Last modified: 2017-12-03 09:04:45 UTC
ClamAV 0.98.6 fixes a heap out of bounds condition with crafted upack packer files. References: https://bugzilla.redhat.com/show_bug.cgi?id=1187050 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9328 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9328 http://lurker.clamav.net/message/20150127.232443.27bcc068.en.html
bugbot adjusting priority
An update workflow for this issue was started. This issue was rated as important. Please submit fixed packages until 2015-02-11. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/60537
This is an autogenerated message for OBS integration: This bug (915512) was mentioned in https://build.opensuse.org/request/show/284469 Factory / clamav
openSUSE-SU-2015:0285-1: An update that fixes four vulnerabilities is now available. Category: security (important) Bug References: 915512,916214,916215,916217 CVE References: CVE-2014-9328,CVE-2015-1461,CVE-2015-1462,CVE-2015-1463 Sources used: openSUSE 13.2 (src): clamav-0.98.6-2.13.1 openSUSE 13.1 (src): clamav-0.98.6-30.1
SUSE-SU-2015:0291-1: An update that fixes four vulnerabilities is now available. Category: security (moderate) Bug References: 915512,916214,916215,916217 CVE References: CVE-2014-9328,CVE-2015-1461,CVE-2015-1462,CVE-2015-1463 Sources used: SUSE Linux Enterprise Server 12 (src): clamav-0.98.6-10.1 SUSE Linux Enterprise Desktop 12 (src): clamav-0.98.6-10.1
SUSE-SU-2015:0298-1: An update that fixes four vulnerabilities is now available. Category: security (important) Bug References: 915512,916214,916215,916217 CVE References: CVE-2014-9328,CVE-2015-1461,CVE-2015-1462,CVE-2015-1463 Sources used: SUSE Linux Enterprise Server 11 SP3 for VMware (src): clamav-0.98.6-0.6.1 SUSE Linux Enterprise Server 11 SP3 (src): clamav-0.98.6-0.6.1 SUSE Linux Enterprise Server 11 SP2 LTSS (src): clamav-0.98.6-0.6.1 SUSE Linux Enterprise Server 11 SP1 LTSS (src): clamav-0.98.6-0.6.1 SUSE Linux Enterprise Server 10 SP4 LTSS (src): clamav-0.98.6-0.8.1 SUSE Linux Enterprise Desktop 11 SP3 (src): clamav-0.98.6-0.6.1
all updates released
This is an autogenerated message for OBS integration: This bug (915512) was mentioned in https://build.opensuse.org/request/show/547654 15.0 / clamav