Cisco has released the free antivirus package ClamAV 1.0.0.

Cisco has introduced a significant new release of the free antivirus package ClamAV 1.0.0. This new branch is notable for its transition to the conventional version numbering scheme 'Major.Minor.Patch' (instead of 0.Version.Patch). The significant version change is also due to modifications in the libclamav library that break ABI compatibility, including the removal of the CLAMAV_PUBLIC namespace, changes to argument types in the cl_strerror function, and the inclusion of symbols for the Rust programming language. The project became part of Cisco in 2013 after the acquisition of Sourcefire, which developed ClamAV and Snort. The project's code is distributed under the GPLv2 license.

The 1.0.0 branch is classified as a long-term support (LTS) release, with maintenance guaranteed for three years. The release of ClamAV 1.0.0 will replace the previous LTS branch ClamAV 0.103, with updates addressing vulnerabilities and critical issues being issued until September 2023. Updates for regular branches not classified as LTS will be published for at least 4 months following the first release of the next branch. The ability to download the signature database for non-LTS branches will also be provided for at least 4 months after the next branch's release.

Key improvements in ClamAV 1.0:

  • Support has been added for decrypting read-only XLS files based on OLE2, encrypted with a default password.
  • The code has been rewritten to implement an all-match mode, where all matches in a file are detected, meaning scanning continues after the first match. The new code is noted as being more reliable and easier to maintain. In this new implementation, a series of conceptual shortcomings that appeared during signature checks in all-match mode have also been addressed. Tests have been added to verify the correctness of the all-match behavior.
  • A callback function clcb_file_inspection() has been added to the API to connect handlers that perform content inspection on files, including those extracted from archives.
  • A function cl_cvdunpack() has been added to the API for unpacking signature archives in CVD format.
  • Scripts for building Docker images with ClamAV have been moved to a separate repository clamav-docker. The Docker image includes header files for the C library.
  • Checks have been added to limit the level of recursion when extracting objects from PDF documents.
  • The limit on the amount of memory allocated when processing untrusted input has been increased, and a warning is now issued when this limit is exceeded.
  • The build process of unit tests for the libclamav-Rust library has been significantly accelerated. Modules written in Rust for ClamAV are now built in a directory shared with ClamAV.
  • The restrictions on checking for overlapping entries in ZIP files have been relaxed, eliminating false warnings when processing slightly modified but non-malicious JAR archives.
  • The minimum and maximum supported versions of LLVM have been defined during the build process. Attempting to build with an overly old or new version will now result in an error message warning of potential compatibility issues.
  • Building with a custom RPATH (the list of directories from which shared libraries are loaded) is now allowed, enabling the relocation of executables after building in a development environment.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster