Recommended update for clamav

Announcement ID: SUSE-RU-2016:1422-1
Rating: moderate
References:
Affected Products:
  • SLES for SAP Applications 11-SP4
  • SUSE Linux Enterprise Server 11 SP4

An update that has one fix can now be installed.

Description:

ClamAV was updated to version 0.99.2, which brings fixes and enhancements:

  • Fix 7z's FolderStartPackStreamIndex array index check.
  • Print all CDBNAME entries for a zip file when using the -z flag.
  • clamunrar: Notice if unpacking comment failed.
  • Use temporary variable for realloc to prevent pointer loss.
  • freshclam: Avoid random data in mirrors.dat.
  • libclamav: Print raw certificate metadata.
  • Fix download and verification of *.cld through PrivateMirrors.
  • Suppress IP notification when using proxy.
  • Remove redundant mempool assignment.
  • Divide out dumpcerts output for better readability.
  • Fix dconf and option handling for nocert and dumpcert.
  • Increase clamd's soft file descriptor to its potential maximum on 64-bit systems.
  • Move libfreshclam config to m4/reorganization.
  • Add 'cdb' datafile to sigtools list of datafile types.
  • Prevent memory allocations on used pointers.
  • Check packSizes prior to dereference
  • Fix inconsistent folder state on failure.
  • Add sanity checks to 7z header parsing.

For a comprehensive list of fixes please refer to the package's change log.

Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

  • SUSE Linux Enterprise Server 11 SP4
    zypper in -t patch slessp4-clamav-12580=1
  • SLES for SAP Applications 11-SP4
    zypper in -t patch slessp4-clamav-12580=1

Package List:

  • SUSE Linux Enterprise Server 11 SP4 (s390x x86_64 i586 ppc64 ia64)
    • clamav-0.99.2-0.14.1
  • SLES for SAP Applications 11-SP4 (ppc64 x86_64)
    • clamav-0.99.2-0.14.1

References: