Mandriva Linux Security Advisory : clamav (MDVSA-2015:221)

medium Nessus Plugin ID 83245

Synopsis

The remote Mandriva Linux host is missing one or more security updates.

Description

Multiple vulnerabilities has been found and corrected in clamav :

Fix infinite loop condition on crafted y0da cryptor file. Identified and patch suggested by Sebastian Andrzej Siewior (CVE-2015-2221).

Fix crash on crafted petite packed file. Reported and patch supplied by Sebastian Andrzej Siewior (CVE-2015-2222).

Fix an infinite loop condition on a crafted xz archive file. This was reported by Dimitri Kirchner and Goulven Guiheux (CVE-2015-2668).

Apply upstream patch for possible heap overflow in Henry Spencer's regex library (CVE-2015-2305).

Fix crash in upx decoder with crafted file. Discovered and patch supplied by Sebastian Andrzej Siewior (CVE-2015-2170).

The updated packages provides a solution for these security issues.

Solution

Update the affected packages.

See Also

http://blog.clamav.net/2015/04/clamav-0987-has-been-released.html

Plugin Details

Severity: Medium

ID: 83245

File Name: mandriva_MDVSA-2015-221.nasl

Version: 2.6

Type: local

Published: 5/5/2015

Updated: 1/14/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:clamav, p-cpe:/a:mandriva:linux:clamav-db, p-cpe:/a:mandriva:linux:clamav-milter, p-cpe:/a:mandriva:linux:clamd, p-cpe:/a:mandriva:linux:lib64clamav-devel, p-cpe:/a:mandriva:linux:lib64clamav6, cpe:/o:mandriva:business_server:1, cpe:/o:mandriva:business_server:2

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Patch Publication Date: 5/4/2015

Reference Information

CVE: CVE-2015-2170, CVE-2015-2221, CVE-2015-2222, CVE-2015-2305, CVE-2015-2668

MDVSA: 2015:221