Cisco ընկերությունը հրապարակել է ClamAV 1.4.6 և 1.5.4 անվճար հակավիրուսային ծրագրերի նոր տարբերակներ, որտեղ շտկվել են խոցելիությունները, որոնցից մի քանիսը կարող են հանգեցնել հարձակողի կոդի执行մանը հատուկ ձևավորված բովանդակություն ստուգելիս։
- CVE-2026-20337 — BUF-ի սահմաններից դուրս գրելու սխալ ZIP արխիվների հատուկ ձևավորված վարման ժամանակ։
- CVE-2026-20345 — Buffer overflow for writing and reading during the handling of incorrect GPT partition names.
- CVE-2026-20339 — Integers overflow in the PESpin decompressor, leading to writing beyond the allocated buffer when iterating through the PE file.
- CVE-2026-20338 — Memory access after its release in the ZIP archive handler.
- CVE-2026-20346 — Integer overflow in the PDF format parser.
- CVE-2026-20347 — Integer overflow in the Mach-O format executable file parser.
- CVE-2026-20348 — Exhaustion of available memory during the parsing of specially formatted XAR files.
- CVE-2025-8088 — Files extraction in an area outside the root of the temporary directory when processing specially formatted RAR archives on the Windows platform.
Ընտանիք: opennet.ru
