Update of the free antivirus package ClamAV 0.101.3

Cisco introduced The corrective release of the free antivirus package ClamAV 0.101.3 addressed a vulnerability that allows for denial of service by transmitting a specially crafted zip archive as an attachment.

The Problem is a variant of a non-recursive 'zip bomb', the unpacking of which requires an extensive amount of time and resources. The essence of the method lies in embedding data in the archive that achieves maximum compression for the zip format — about 28 million times. For example, a specially prepared zip file of 10 MB would unpack to about 281 TB of data, while a 46 MB file would yield 4.5 PB.

Additionally, the new release updates the built-in library libmspack, which resolved contains a buffer overflow (CVE-2019-1010305) that leads to data leakage when opening a specially crafted chm file.

At the same time, a beta version of the new ClamAV 0.102 branch has been introduced, which transfers the functionality of on-access scanning (scanning at the moment of file opening) from clamd to a separate process called clamonacc, implemented similarly to clamdscan and clamav-milter. This change allows clamd to operate under a regular user without the need for root privileges.
The new branch also adds support for egg (ESTsoft) archives and significantly revamps the freshclam program, which now supports HTTPS and the ability to work with mirrors processing requests on network ports other than 80.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster