The release of the free antivirus package ClamAV 0.103.2 has been announced, which addresses several vulnerabilities:
- CVE-2021-1386 — privilege escalation on Windows due to unsafe DLL UnRAR loading (a local user can place their DLL posing as the UnRAR library to execute code with system privileges).
- CVE-2021-1252 — looping when processing specially crafted Excel XLM files.
- CVE-2021-1404 — process crash when handling specially crafted PDF documents.
- CVE-2021-1405 — crash due to dereferencing NULL pointers in the email parser.
- Memory leak in PNG image parsing code.
Among the non-security related changes is the transition of the outdated SafeBrowsing settings into a non-functioning placeholder due to Google's change in access conditions to the Safe Browsing API. The FreshClam utility has improved handling of HTTP codes 304, 403, and 429, and the mirrors.dat file has been returned to the database directory.
Source: opennet.ru
