Cisco has released the free antivirus package ClamAV 0.105.

Cisco has introduced a significant new release of the free antivirus package ClamAV 0.105.0, as well as corrective releases ClamAV 0.104.3 and 0.103.6, which fix vulnerabilities and bugs. It is worth noting that the project came under Cisco's control in 2013 after the acquisition of Sourcefire, which developed ClamAV and Snort. The project code is distributed under the GPLv2 license.

Key improvements in ClamAV 0.105:

  • The Rust language compiler has been included as a mandatory build dependency. At least version 1.56 of Rust is required for compilation. Necessary Rust libraries are included in the main ClamAV package.
  • The code for incremental database archive updates (CDIFF) has been rewritten in Rust. The new implementation has significantly accelerated the application of updates that remove a large number of signatures from the database. This is the first module rewritten in Rust.
  • Default limit values have been increased:
    • MaxScanSize: 100M > 400M
    • MaxFileSize: 25M > 100M
    • StreamMaxLength: 25M > 100M
    • PCREMaxFileSize: 25M > 100M
    • MaxEmbeddedPE: 10M > 40M
    • MaxHTMLNormalize: 10M > 40M
    • MaxScriptNormalize: 5M > 20M
    • MaxHTMLNoTags: 2M > 8M
    • The maximum line size in the configuration files freshclam.conf and clamd.conf has been increased from 512 to 1024 characters (when specifying access tokens, the DatabaseMirror parameter could exceed 512 bytes).
  • To identify images used for phishing or spreading malware, support for a new type of logical signature has been implemented, using the fuzzy hashing method, which allows for detecting similar objects with a certain degree of probability. The 'sigtool —fuzzy-img' command can be used to generate a fuzzy hash for an image.
  • ClamScan and ClamDScan now include the ability to scan process memory. This feature has been migrated from the ClamWin package and is specific to the Windows platform. Options '—memory', '—kill', and '—unload' have been added to ClamScan and ClamDScan on the Windows platform.
  • Runtime components for executing bytecode based on LLVM have been updated. A JIT-compilation mode has been proposed to increase scanning performance compared to the default bytecode interpreter. Support for older versions of LLVM has been discontinued; versions 8 to 12 of LLVM can now be used.
  • In Clamd, a setting called GenerateMetadataJson has been added, equivalent to the ‘--gen-json’ option in clamscan, which writes scanning progress metadata to a file named metadata.json in JSON format.
  • Support for building with the external library TomsFastMath (libtfm) has been provided, enabled using the options ‘-D ENABLE_EXTERNAL_TOMSFASTMATH=ON’, ‘-D TomsFastMath_INCLUDE_DIR=’, and ‘-D TomsFastMath_LIBRARY=’. The included copy of the TomsFastMath library has been updated to version 0.13.1.
  • The Freshclam utility has improved its behavior when handling the ReceiveTimeout timeout, which now only interrupts stalled downloads and does not terminate active slow downloads over poor connections.
  • Support for building ClamdTop using the ncursesw library when ncurses is unavailable has been added.
  • Fixed vulnerabilities:
    • CVE-2022-20803 — double free in the OLE2 file parser.
    • CVE-2022-20770 — infinite loop in the CHM file parser.
    • CVE-2022-20796 — crash due to dereferencing a null pointer in cache verification code.
    • CVE-2022-20771 — infinite loop in the TIFF file parser.
    • CVE-2022-20785 — memory leak in the HTML parser and Javascript normalizer.
    • CVE-2022-20792 — buffer overflow in the signature database loading module.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster