Mailing List Archive

[clamav-users] ClamAV CVE's
The most current version is ClamAV 0.100.3 for Ubuntu 18.04.3 LTS. Is
there a list of CVE's that I can reference in a bug report to try and
get ClamAV updated to the latest version?

Thank you
Chris

--
Chris
KeyID 0xE372A7DA98E6705C
31.11972; -97.90167 (Elev. 1092 ft)
16:10:12 up 9 days, 7:27, 1 user, load average: 1.71, 1.15, 0.96
Description: Ubuntu 18.04.3 LTS, kernel 5.0.0-25-generic
Re: [clamav-users] ClamAV CVE's [ In reply to ]
I'm don't see anything specifying 0.100.3 yet: <https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=clamav <https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=clamav>>.

-Al-
ClamXAV user

On Aug 22, 2019, at 14:12, Chris Pollock via clamav-users <clamav-users@lists.clamav.net> wrote:
> The most current version is ClamAV 0.100.3 for Ubuntu 18.04.3 LTS. Is
> there a list of CVE's that I can reference in a bug report to try and
> get ClamAV updated to the latest version?
>
> Thank you
> Chris
>
> --
> Chris
Re: [clamav-users] ClamAV CVE's [ In reply to ]
On Thu, 2019-08-22 at 16:58 -0700, Al Varnell via clamav-users wrote:
> I'm don't see anything specifying 0.100.3 yet: <
> https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=clamav>.
>
> -Al-
> ClamXAV user

Thanks Al, maybe I'm reading the listing wrong but these
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1798
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1788
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1787

refer to Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior.
Wouldn't 0.100.3 fit into those parameters?

>
> On Aug 22, 2019, at 14:12, Chris Pollock via clamav-users <
> clamav-users@lists.clamav.net> wrote:
> > The most current version is ClamAV 0.100.3 for Ubuntu 18.04.3 LTS.
> > Is
> > there a list of CVE's that I can reference in a bug report to try
> > and
> > get ClamAV updated to the latest version?
> >
> > Thank you
> > Chris
> >
> > --
> > Chris
>
> _______________________________________________
>
> clamav-users mailing list
> clamav-users@lists.clamav.net
> https://lists.clamav.net/mailman/listinfo/clamav-users
>
>
> Help us build a comprehensive ClamAV guide:
> https://github.com/vrtadmin/clamav-faq
>
> http://www.clamav.net/contact.html#ml
--
Chris
KeyID 0xE372A7DA98E6705C
31.11972; -97.90167 (Elev. 1092 ft)
19:34:56 up 9 days, 10:52, 1 user, load average: 1.03, 0.77, 0.58
Description: Ubuntu 18.04.3 LTS, kernel 5.0.0-25-generic
Re: [clamav-users] ClamAV CVE's [ In reply to ]
Yes, I'm sorry, I was thinking of 0.101.3 when I said that.

-Al-

On Thu, Aug 22, 2019 at 17:37 PM, Chris Pollock via clamav-users wrote:
> On Thu, 2019-08-22 at 16:58 -0700, Al Varnell via clamav-users wrote:
>> I'm don't see anything specifying 0.100.3 yet: <
>> https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=clamav <https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=clamav>>.
>>
>> -Al-
>> ClamXAV user
>
> Thanks Al, maybe I'm reading the listing wrong but these
> https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1798 <https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1798>
> https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1788 <https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1788>
> https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1787 <https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1787>
>
> refer to Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior.
> Wouldn't 0.100.3 fit into those parameters?
>
>>
>> On Aug 22, 2019, at 14:12, Chris Pollock via clamav-users <
>> clamav-users@lists.clamav.net <mailto:clamav-users@lists.clamav.net>> wrote:
>>> The most current version is ClamAV 0.100.3 for Ubuntu 18.04.3 LTS.
>>> Is
>>> there a list of CVE's that I can reference in a bug report to try
>>> and
>>> get ClamAV updated to the latest version?
>>>
>>> Thank you
>>> Chris
>>>
>>> --
>>> Chris
>>
>> _______________________________________________
>>
>> clamav-users mailing list
>> clamav-users@lists.clamav.net <mailto:clamav-users@lists.clamav.net>
>> https://lists.clamav.net/mailman/listinfo/clamav-users <https://lists.clamav.net/mailman/listinfo/clamav-users>
>>
>>
>> Help us build a comprehensive ClamAV guide:
>> https://github.com/vrtadmin/clamav-faq <https://github.com/vrtadmin/clamav-faq>
>>
>> http://www.clamav.net/contact.html#ml <http://www.clamav.net/contact.html#ml>
Re: [clamav-users] ClamAV CVE's [ In reply to ]
On Thu, 2019-08-22 at 17:46 -0700, Al Varnell via clamav-users wrote:
> Yes, I'm sorry, I was thinking of 0.101.3 when I said that.
>
> -Al-
>
No problem, so, I can reference these to hopefully get an update built
for 18.04. I'll file a bug report tomorrow some time.
Thanks Al.

> On Thu, Aug 22, 2019 at 17:37 PM, Chris Pollock via clamav-users
> wrote:
> > On Thu, 2019-08-22 at 16:58 -0700, Al Varnell via clamav-users
> > wrote:
> > > I'm don't see anything specifying 0.100.3 yet: <
> > > https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=clamav>;.
> > >
> > > -Al-
> > > ClamXAV user
> >
> > Thanks Al, maybe I'm reading the listing wrong but these
> > https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1798
> > https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1788
> > https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1787
> >
> > refer to Clam AntiVirus (ClamAV) Software versions 0.101.1 and
> > prior.
> > Wouldn't 0.100.3 fit into those parameters?
> >
> > > On Aug 22, 2019, at 14:12, Chris Pollock via clamav-users <
> > > clamav-users@lists.clamav.net> wrote:
> > > > The most current version is ClamAV 0.100.3 for Ubuntu 18.04.3
> > > > LTS.
> > > > Is
> > > > there a list of CVE's that I can reference in a bug report to
> > > > try
> > > > and
> > > > get ClamAV updated to the latest version?
> > > >
> > > > Thank you
> > > > Chris
> > > >
> > > > --
> > > > Chris
> > >
> > > _______________________________________________
> > >
> > > clamav-users mailing list
> > > clamav-users@lists.clamav.net
> > > https://lists.clamav.net/mailman/listinfo/clamav-users
> > >
> > >
> > > Help us build a comprehensive ClamAV guide:
> > > https://github.com/vrtadmin/clamav-faq
> > >
> > > http://www.clamav.net/contact.html#ml
>
>
>
> _______________________________________________
>
> clamav-users mailing list
> clamav-users@lists.clamav.net
> https://lists.clamav.net/mailman/listinfo/clamav-users
>
>
> Help us build a comprehensive ClamAV guide:
> https://github.com/vrtadmin/clamav-faq
>
> http://www.clamav.net/contact.html#ml
--
Chris
KeyID 0xE372A7DA98E6705C
31.11972; -97.90167 (Elev. 1092 ft)
19:52:06 up 9 days, 11:09, 1 user, load average: 1.74, 1.27, 0.98
Description: Ubuntu 18.04.3 LTS, kernel 5.0.0-25-generic
Re: [clamav-users] ClamAV CVE's [ In reply to ]
Chris, Al,

I think the CVE description is slightly misleading. 0.100.3 was created at the same time as 0.101.2 and addressed each of those:
https://blog.clamav.net/2019/03/clamav-01012-and-01003-patches-have.html

However, these issues affect all versions prior to 0.101.4, as we did not create a patch for 0.100 this time:
* CVE-2019-12625: zip-bomb scan time issue.
* CVE-2019-12900: bz2 buffer overwrite in NSIS parser's copy of libbz2 decompression code.

And this issue affects all versions prior to 0.101.3:
* CVE-2019-1010305: libmspack buffer overflow in CHM file parser in bundled version of libmspack (if using).

This is still reason enough to update.
As a side note, CVE-2019-12625 is still private though it was supposed to be published yesterday. Will get it opened up as soon as possible.

-Micah

?On 8/22/19, 8:54 PM, "clamav-users on behalf of Chris Pollock via clamav-users" <clamav-users-bounces@lists.clamav.net on behalf of clamav-users@lists.clamav.net> wrote:

On Thu, 2019-08-22 at 17:46 -0700, Al Varnell via clamav-users wrote:
> Yes, I'm sorry, I was thinking of 0.101.3 when I said that.
>
> -Al-
>
No problem, so, I can reference these to hopefully get an update built
for 18.04. I'll file a bug report tomorrow some time.
Thanks Al.

> On Thu, Aug 22, 2019 at 17:37 PM, Chris Pollock via clamav-users
> wrote:
> > On Thu, 2019-08-22 at 16:58 -0700, Al Varnell via clamav-users
> > wrote:
> > > I'm don't see anything specifying 0.100.3 yet: <
> > > https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=clamav>;.
> > >
> > > -Al-
> > > ClamXAV user
> >
> > Thanks Al, maybe I'm reading the listing wrong but these
> > https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1798
> > https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1788
> > https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1787
> >
> > refer to Clam AntiVirus (ClamAV) Software versions 0.101.1 and
> > prior.
> > Wouldn't 0.100.3 fit into those parameters?
> >
> > > On Aug 22, 2019, at 14:12, Chris Pollock via clamav-users <
> > > clamav-users@lists.clamav.net> wrote:
> > > > The most current version is ClamAV 0.100.3 for Ubuntu 18.04.3
> > > > LTS.
> > > > Is
> > > > there a list of CVE's that I can reference in a bug report to
> > > > try
> > > > and
> > > > get ClamAV updated to the latest version?
> > > >
> > > > Thank you
> > > > Chris
> > > >
> > > > --
> > > > Chris
> > >
> > > _______________________________________________
> > >
> > > clamav-users mailing list
> > > clamav-users@lists.clamav.net
> > > https://lists.clamav.net/mailman/listinfo/clamav-users
> > >
> > >
> > > Help us build a comprehensive ClamAV guide:
> > > https://github.com/vrtadmin/clamav-faq
> > >
> > > http://www.clamav.net/contact.html#ml
>
>
>
> _______________________________________________
>
> clamav-users mailing list
> clamav-users@lists.clamav.net
> https://lists.clamav.net/mailman/listinfo/clamav-users
>
>
> Help us build a comprehensive ClamAV guide:
> https://github.com/vrtadmin/clamav-faq
>
> http://www.clamav.net/contact.html#ml
--
Chris
KeyID 0xE372A7DA98E6705C
31.11972; -97.90167 (Elev. 1092 ft)
19:52:06 up 9 days, 11:09, 1 user, load average: 1.74, 1.27, 0.98
Description: Ubuntu 18.04.3 LTS, kernel 5.0.0-25-generic




_______________________________________________

clamav-users mailing list
clamav-users@lists.clamav.net
https://lists.clamav.net/mailman/listinfo/clamav-users


Help us build a comprehensive ClamAV guide:
https://github.com/vrtadmin/clamav-faq

http://www.clamav.net/contact.html#ml
Re: [clamav-users] ClamAV CVE's [ In reply to ]
On 22.08.19 16:12, Chris Pollock via clamav-users wrote:
>The most current version is ClamAV 0.100.3 for Ubuntu 18.04.3 LTS. Is
>there a list of CVE's that I can reference in a bug report to try and
>get ClamAV updated to the latest version?

Debian has this:

https://security-tracker.debian.org/tracker/source-package/clamav
...which currently only links to:
https://security-tracker.debian.org/tracker/CVE-2019-12625

and ubuntu has this:

https://people.canonical.com/~ubuntu-security/cve/pkg/clamav.html
...which currently only links to:
https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-12625.html

I haven't looked what the "needs-triage" means.

--
Matus UHLAR - fantomas, uhlar@fantomas.sk ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
They that can give up essential liberty to obtain a little temporary
safety deserve neither liberty nor safety. -- Benjamin Franklin, 1759

_______________________________________________

clamav-users mailing list
clamav-users@lists.clamav.net
https://lists.clamav.net/mailman/listinfo/clamav-users


Help us build a comprehensive ClamAV guide:
https://github.com/vrtadmin/clamav-faq

http://www.clamav.net/contact.html#ml
Re: [clamav-users] ClamAV CVE's [ In reply to ]
On Fri, 2019-08-23 at 18:47 +0200, Matus UHLAR - fantomas wrote:
> On 22.08.19 16:12, Chris Pollock via clamav-users wrote:
> > The most current version is ClamAV 0.100.3 for Ubuntu 18.04.3 LTS.
> > Is
> > there a list of CVE's that I can reference in a bug report to try
> > and
> > get ClamAV updated to the latest version?
>
> Debian has this:
>
> https://security-tracker.debian.org/tracker/source-package/clamav
> ...which currently only links to:
> https://security-tracker.debian.org/tracker/CVE-2019-12625
>
> and ubuntu has this:
>
> https://people.canonical.com/~ubuntu-security/cve/pkg/clamav.html
> ...which currently only links to:
>
https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-12625.html
>
> I haven't looked what the "needs-triage" means.
>
Hi Matus, I believe this actually relates to the 0.100.3 release.

https://launchpad.net/ubuntu/bionic/+source/clamav

Here's the bug report I did back in March of this year to get the
update done. I'll go in and file a new one this afternoon to see about
getting it updated to the most current release.

https://bugs.launchpad.net/ubuntu/+source/clamav/+bug/1822503

Chris

--
Chris
KeyID 0xE372A7DA98E6705C
31.11972; -97.90167 (Elev. 1092 ft)
15:21:54 up 10 days, 6:38, 1 user, load average: 0.97, 0.92, 0.69
Description: Ubuntu 18.04.3 LTS, kernel 5.0.0-25-generic
Re: [clamav-users] ClamAV CVE's [ In reply to ]
>> On 22.08.19 16:12, Chris Pollock via clamav-users wrote:
>> > The most current version is ClamAV 0.100.3 for Ubuntu 18.04.3 LTS.
>> > Is
>> > there a list of CVE's that I can reference in a bug report to try
>> > and
>> > get ClamAV updated to the latest version?

>On Fri, 2019-08-23 at 18:47 +0200, Matus UHLAR - fantomas wrote:
>> Debian has this:
>>
>> https://security-tracker.debian.org/tracker/source-package/clamav
>> ...which currently only links to:
>> https://security-tracker.debian.org/tracker/CVE-2019-12625
>>
>> and ubuntu has this:
>>
>> https://people.canonical.com/~ubuntu-security/cve/pkg/clamav.html
>> ...which currently only links to:
>>
>https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-12625.html
>>
>> I haven't looked what the "needs-triage" means.

On 23.08.19 15:28, Chris Pollock via clamav-users wrote:
>Hi Matus, I believe this actually relates to the 0.100.3 release.
>
>https://launchpad.net/ubuntu/bionic/+source/clamav
>
>Here's the bug report I did back in March of this year to get the
>update done. I'll go in and file a new one this afternoon to see about
>getting it updated to the most current release.
>
>https://bugs.launchpad.net/ubuntu/+source/clamav/+bug/1822503

the first vulnerability mentioned there is CVE-2019-1787.

debian reports it fixed in debian packages:
https://security-tracker.debian.org/tracker/CVE-2019-1787

I believe it's the same for ubuntu packages:
https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-1787

I haven't looked at the rest of vulnerabilities, they may be still present
(e.g. ignored because evaluated as minor or not applicable).

What I want to say is, that whole fact about debian and ubuntu having older
than newest clamav packages does NOT mean that the security bugs are not
fixed there.

What was already mentioned is that distribution packagers do backport fixes
to older versions to prevent incompatibilities introduced by newer packages,
pretty summarised here:

https://lists.clamav.net/pipermail/clamav-users/2019-August/008248.html


--
Matus UHLAR - fantomas, uhlar@fantomas.sk ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
Boost your system's speed by 500% - DEL C:\WINDOWS\*.*

_______________________________________________

clamav-users mailing list
clamav-users@lists.clamav.net
https://lists.clamav.net/mailman/listinfo/clamav-users


Help us build a comprehensive ClamAV guide:
https://github.com/vrtadmin/clamav-faq

http://www.clamav.net/contact.html#ml