buildroot/package/clamav
Bernd Kuhls 19748514b8 package/clamav: security bump version to 0.102.2
Fixes CVE-2020-3123: A vulnerability in the Data-Loss-Prevention (DLP)
module in Clam AntiVirus (ClamAV) Software versions 0.102.1 and 0.102.0
could allow an unauthenticated, remote attacker to cause a denial of service
condition on an affected device.  The vulnerability is due to an
out-of-bounds read affecting users that have enabled the optional DLP
feature.  An attacker could exploit this vulnerability by sending a crafted
email file to an affected device.  An exploit could allow the attacker to
cause the ClamAV scanning process crash, resulting in a denial of service
condition.

Release notes:
https://lists.clamav.net/pipermail/clamav-announce/2020/000045.html

Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2020-02-06 21:01:56 +01:00
..
0001-clamdscan-proto.c-fix-build-error-due-to-missing-soc.patch
0002-mbox-do-not-use-backtrace-if-using-uClibc-without-ba.patch
clamav.hash package/clamav: security bump version to 0.102.2 2020-02-06 21:01:56 +01:00
clamav.mk package/clamav: security bump version to 0.102.2 2020-02-06 21:01:56 +01:00
Config.in package/clamav: select musl-fts if not glibc 2019-10-13 22:19:33 +02:00