ClamAV 1.4.6 և 1.5.4 հակավիրուսային փաթեթի թարմացում 8 խոցելիություններ շտկվելուց հետո

Cisco ընկերությունը հրապարակել է ClamAV 1.4.6 և 1.5.4 անվճար հակավիրուսային ծրագրերի նոր տարբերակներ, որտեղ շտկվել են խոցելիությունները, որոնցից մի քանիսը կարող են հանգեցնել հարձակողի կոդի执行մանը հատուկ ձևավորված բովանդակություն ստուգելիս։

  • CVE-2026-20337 — BUF-ի սահմաններից դուրս գրելու սխալ ZIP արխիվների հատուկ ձևավորված վարման ժամանակ։
  • CVE-2026-20345 — Buffer overflow for writing and reading during the handling of incorrect GPT partition names.
  • CVE-2026-20339 — Integers overflow in the PESpin decompressor, leading to writing beyond the allocated buffer when iterating through the PE file.
  • CVE-2026-20338 — Memory access after its release in the ZIP archive handler.
  • CVE-2026-20346 — Integer overflow in the PDF format parser.
  • CVE-2026-20347 — Integer overflow in the Mach-O format executable file parser.
  • CVE-2026-20348 — Exhaustion of available memory during the parsing of specially formatted XAR files.
  • CVE-2025-8088 — Files extraction in an area outside the root of the temporary directory when processing specially formatted RAR archives on the Windows platform.

Ընտանիք: opennet.ru

Գնել հուսալի հյուրընկալում DDoS պաշտպանությամբ, VPS VDS սերվերներով 🔥 Գնել հուսալի հյուրընկալում DDoS պաշտպանությամբ, VPS VDS սերվերներով | ProHoster