2019年11月7日 星期四

[USN-4146-1] ClamAV vulnerabilities

---------- Forwarded message ---------
From: Marc Deslauriers
Date: Oct 2, 2019 8:05PM

It was discovered that ClamAV incorrectly handled unpacking ZIP files. A
remote attacker could possibly use this issue to cause ClamAV to crash,
resulting in a denial of service. (CVE-2019-12625)

It was discovered that ClamAV incorrectly handled unpacking bzip2 files. A
remote attacker could use this issue to cause ClamAV to crash, resulting in
a denial of service, or possibly execute arbitrary code. (CVE-2019-12900)

References:
  https://usn.ubuntu.com/4146-1
  CVE-2019-12625, CVE-2019-12900

沒有留言:

張貼留言