the release of the free antivirus package ClamAV 0.101.4, which addresses a vulnerability () in the implementation of the bzip2 archive unpacker that could lead to memory areas being overwritten outside the allocated buffer when processing an excessive number of selectors.
The new version also blocks a workaround for creating
non-recursive ââ, protection against which was proposed in . The previously added protection focused on limiting resource consumption but did not consider the possibility of creating âzip bombsâ that manipulate the file processing time. The scanning time for a file is now limited to two minutes. To change the set limit, the option âclamscan âmax-scantimeâ and the MaxScanTime directive for the clamd configuration file have been proposed.
Source: opennet.ru
