From 22efaa5b0e21a170370a7101073e5d6aeb7f2bd4 Mon Sep 17 00:00:00 2001 From: Franco Fichtner Date: Thu, 4 Apr 2019 11:09:34 +0200 Subject: [PATCH] security/vuxml: sync with upstream Taken from: HardenedBSD --- security/vuxml/vuln.xml | 36 ++++++++++++++++++++++++++++++++++++ 1 file changed, 36 insertions(+) diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 1cc914b649e8..9bd0950f37dc 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -58,6 +58,42 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + clamav -- multiple vulnerabilities + + + clamav + 0.101.2,1 + + + + +

Clamav reports:

+
+

An out-of-bounds heap read condition may occur when scanning PDF documents

+

An out-of-bounds heap read condition may occur when scanning PE files

+

An out-of-bounds heap write condition may occur when scanning OLE2 files

+

An out-of-bounds heap read condition may occur when scanning malformed PDF documents

+

A path-traversal write condition may occur as a result of improper input validation when scanning RAR archives

+

A use-after-free condition may occur as a result of improper error handling when scanning nested RAR archives

+
+ +
+ + https://blog.clamav.net/2019/03/clamav-01012-and-01003-patches-have.html + CVE-2019-1787 + CVE-2019-1789 + CVE-2019-1788 + CVE-2019-1786 + CVE-2019-1785 + CVE-2019-1798 + + + 2019-03-29 + 2019-04-05 + +
+ Gitlab -- Multiple vulnerabilities