release of the free antivirus package , which addresses the CVE-2020-3123 vulnerability in the DLP (data-loss-prevention) mechanism aimed at blocking the leakage of credit card numbers. Due to a boundary check error, it is possible to create conditions for reading data from outside the allocated buffer, which can be exploited for a DoS attack and trigger a crash of the worker process. Additionally, a missing fix from the 0.102 branch for the CVE-2019-1785 vulnerability has been included, allowing data to be written to areas outside the directory used during unpacking when scanning specially crafted RAR archives.
The new release also fixes several non-security issues, resolves a crash when loading the new database version in freshclam, addresses a memory leak in the email parser, improves the performance of scanning PDF files on the Windows platform, strengthens ARJ archive verification, enhances the handling of malformed PDF files, and adds support for autoconf 2.69 and automake 1.15.
Source: opennet.ru
