Cisco has released the ClamAV 1.3.0 antivirus package and addressed a serious vulnerability

After six months of development, Cisco has released the free antivirus package ClamAV 1.3.0. The project came under Cisco's control in 2013 following the acquisition of Sourcefire, the company that develops ClamAV and Snort. The project's code is distributed under the GPLv2 license. The 1.3.0 branch is classified as a regular (non-LTS) version, with updates published for at least four months following the release of the first version of the subsequent branch. The ability to download signature databases for non-LTS branches is also guaranteed for at least another four months after the release of the next branch.

Key Improvements in ClamAV 1.3:

  • Support for extracting and checking attachments used in Microsoft OneNote files has been added. Parsing the OneNote format is enabled by default, but can be disabled by setting 'ScanOneNote no' in clamd.conf, using the command line option '--scan-onenote=no' when running the clamscan utility, or adding the flag CL_SCAN_PARSE_ONENOTE to the options.parse parameter when using libclamav.
  • ClamAV has been successfully built for the BeOS-like operating system Haiku.
  • In clamd, a check for the existence of the directory for temporary files specified in clamd.conf via the TemporaryDirectory directive has been added. If this directory is missing, the process now terminates with an error message.
  • When configuring the build of static libraries in CMake, the installation of the static libraries libclamav_rust, libclammspack, libclamunrar_iface, and libclamunrar used in libclamav has been ensured.
  • File type detection for compiled Python scripts (.pyc) has been implemented. The file type is passed as a string parameter CL_TYPE_PYTHON_COMPILED, which is supported in the functions clcb_pre_cache, clcb_pre_scan, and clcb_file_inspection.
  • Support for decrypting PDF documents with empty passwords has been improved.

Simultaneously, updates for ClamAV 1.2.2 and 1.0.5 have been released, fixing two vulnerabilities affecting the branches 0.104, 0.105, 1.0, 1.1, and 1.2:

  • CVE-2024-20328 — a command injection vulnerability during file checks in clamd due to a flaw in the implementation of the 'VirusEvent' directive used to execute arbitrary commands when a virus is detected. Details of the vulnerability's exploitation have not yet been disclosed; it is only known that the issue was resolved by disabling support in VirusEvent for the string formatting parameter '%f', which was replaced by the name of the infected file.

    It seems that the attack involves transmitting a specially crafted name of an infected file containing special characters that are not escaped when executing the command specified in VirusEvent. Notably, a similar vulnerability was addressed back in 2004 by removing support for the ‘%f’ substitution, which was later reintroduced in the release of ClamAV 0.104, leading to the resurgence of the old vulnerability. In the old vulnerability, to execute its command during a virus scan, it was sufficient to create a file named ‘; mkdir owned’ and write a test virus signature into it.

  • CVE-2024-20290 — a buffer overflow in the code parsing OLE2-formatted files, which a remote unauthenticated attacker can exploit to cause a denial of service (crash the scanning process). The issue arises from improper end-of-line checks during content scanning, leading to reading from outside the buffer boundary.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster