ClamAV 0.101.4 free antivirus package update with vulnerabilities fixed

Formed release of the free antivirus package ClamAV 0.101.4, which eliminates the vulnerability (CVE-2019-12900) in the bzip2 archive decompressor implementation, which can lead to overwriting memory areas outside the allocated buffer when processing too many selectors.

The new version also blocks the workaround for creating
non-recursive "zip bomb", protection against which was proposed in last issue. The protection added earlier was focused on limiting resource consumption, but did not take into account the possibility of creating β€œzip bombs” that manipulate the duration of the file processing process. The time to scan a file is now limited to two minutes. To change the set limit, the β€œclamscan β€”max-scantime” option and the MaxScanTime directive for the clamd configuration file are proposed.

Source: opennet.ru

Add a comment