Bugzilla – Bug 916217
VUL-0: CVE-2015-1461: clamav: Remote attackers can have unspecified impact via Yoda's crypter or mew packer files
Last modified: 2017-12-03 09:04:55 UTC
CVE-2015-1461 ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted (1) Yoda's crypter or (2) mew packer file, related to a "heap out of bounds condition." References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-1461 http://www.cvedetails.com/cve/CVE-2015-1461/
An update workflow for this issue was started. This issue was rated as important. Please submit fixed packages until 2015-02-11. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/60537
bugbot adjusting priority
This is an autogenerated message for OBS integration: This bug (916217) was mentioned in https://build.opensuse.org/request/show/284469 Factory / clamav
openSUSE-SU-2015:0285-1: An update that fixes four vulnerabilities is now available. Category: security (important) Bug References: 915512,916214,916215,916217 CVE References: CVE-2014-9328,CVE-2015-1461,CVE-2015-1462,CVE-2015-1463 Sources used: openSUSE 13.2 (src): clamav-0.98.6-2.13.1 openSUSE 13.1 (src): clamav-0.98.6-30.1
SUSE-SU-2015:0291-1: An update that fixes four vulnerabilities is now available. Category: security (moderate) Bug References: 915512,916214,916215,916217 CVE References: CVE-2014-9328,CVE-2015-1461,CVE-2015-1462,CVE-2015-1463 Sources used: SUSE Linux Enterprise Server 12 (src): clamav-0.98.6-10.1 SUSE Linux Enterprise Desktop 12 (src): clamav-0.98.6-10.1
SUSE-SU-2015:0298-1: An update that fixes four vulnerabilities is now available. Category: security (important) Bug References: 915512,916214,916215,916217 CVE References: CVE-2014-9328,CVE-2015-1461,CVE-2015-1462,CVE-2015-1463 Sources used: SUSE Linux Enterprise Server 11 SP3 for VMware (src): clamav-0.98.6-0.6.1 SUSE Linux Enterprise Server 11 SP3 (src): clamav-0.98.6-0.6.1 SUSE Linux Enterprise Server 11 SP2 LTSS (src): clamav-0.98.6-0.6.1 SUSE Linux Enterprise Server 11 SP1 LTSS (src): clamav-0.98.6-0.6.1 SUSE Linux Enterprise Server 10 SP4 LTSS (src): clamav-0.98.6-0.8.1 SUSE Linux Enterprise Desktop 11 SP3 (src): clamav-0.98.6-0.6.1
all updates released
This is an autogenerated message for OBS integration: This bug (916217) was mentioned in https://build.opensuse.org/request/show/547654 15.0 / clamav