Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 338226 - <app-antivirus/clamav-0.96.4: Security bump (CVE-2010-{0405,3434})
Summary: <app-antivirus/clamav-0.96.4: Security bump (CVE-2010-{0405,3434})
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High enhancement (vote)
Assignee: Gentoo Security
URL: http://lurker.clamav.net/message/2010...
Whiteboard: B1 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2010-09-20 20:26 UTC by Michael Orlitzky
Modified: 2011-10-23 14:59 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michael Orlitzky gentoo-dev 2010-09-20 20:26:45 UTC
Released today. Source & Changelog:

  http://www.clamav.net/lang/en/download/sources/
Comment 1 Christian Ruppert (idl0r) gentoo-dev 2010-09-20 21:57:45 UTC
clamav-0.96.3 is now in our software repository. It will be available on the mirrors soon. Thank you for your bug report.
Comment 2 Stefan Behte (RETIRED) gentoo-dev Security 2010-09-22 15:21:15 UTC
Repopening to investigate this later:

Mon Sep 20 14:16:59 CEST 2010 (acab)
------------------------------------
 * libclamav/nsis/bzlib.cld sys: port upstream fixes for CVE-2010-0405,
				 check for buggy bzip2 (bb#2230, bb#2231)
Comment 3 Hanno Böck gentoo-dev 2010-09-22 18:50:01 UTC
I think the bzip-issue doesn't affect us as we don't use the bundled bzip2-code (though not sure about it).But that also sounds like it's security relevant:Mon Sep 20 14:50:34 EEST 2010 (edwin)------------------------------------- * libclamav/pdf.c: Add missing boundscheck to pdf code (bb #2226)The referenced bug is not visible to the public, so it's likely a security issue.
Comment 4 Marcin Mirosław 2010-10-30 13:33:17 UTC
There is new version 0.96.4 , http://git.clamav.net/gitweb?p=clamav-devel.git;a=blob_plain;f=ChangeLog;hb=clamav-0.96.4
Comment 5 Tim Sammut (RETIRED) gentoo-dev 2010-11-18 19:54:56 UTC
(In reply to comment #3)
> I think the bzip-issue doesn't affect us as we don't use the bundled bzip2-code
> (though not sure about it).But that also sounds like it's security relevant:Mon
> Sep 20 14:50:34 EEST 2010 (edwin)------------------------------------- *
> libclamav/pdf.c: Add missing boundscheck to pdf code (bb #2226)The referenced
> bug is not visible to the public, so it's likely a security issue.
> 

Agreed and that is listed as fixed in 0.96.3. 0.96.4 is in the tree thanks to Bug 345189. Unless @antivirus objects...

Arches, please test and mark stable:
=app-antivirus/clamav-0.96.4
Target keywords : "alpha amd64 hppa ia64 ppc ppc64 sparc x86" 


Comment 6 Thomas Kahle (RETIRED) gentoo-dev 2010-11-19 14:32:41 UTC
x86 done thanks.
Comment 7 Jeroen Roovers (RETIRED) gentoo-dev 2010-11-19 16:41:33 UTC
Stable for HPPA PPC.
Comment 8 Markos Chandras (RETIRED) gentoo-dev 2010-11-19 19:57:18 UTC
amd64 done
Comment 9 Raúl Porcel (RETIRED) gentoo-dev 2010-11-20 12:20:14 UTC
alpha/ia64/sparc stable
Comment 10 Brent Baude (RETIRED) gentoo-dev 2010-11-25 15:39:42 UTC
On ppc64 64ul, getting TOC errors on clamav now 

/usr/lib/gcc/powerpc64-unknown-linux-gnu/4.3.4/../../../../powerpc64-unknown-linux-gnu/bin/ld: c++/.libs/libclamavcxx.a(LegalizeVectorTypes.o)(.text+0x16bd8): sibling call optimization to `llvm::DAGTypeLegalizer::GetScalarizedVector(llvm::SDValue)' does not allow automatic multiple TOCs; recompile with -mminimal-toc or -fno-optimize-sibling-calls, or make `llvm::DAGTypeLegalizer::GetScalarizedVector(llvm::SDValue)' extern
/usr/lib/gcc/powerpc64-unknown-linux-gnu/4.3.4/../../../../powerpc64-unknown-linux-gnu/bin/ld: c++/.libs/libclamavcxx.a(LegalizeVectorTypes.o)(.text+0x17aac): sibling call optimization to `llvm::DAGTypeLegalizer::GetScalarizedVector(llvm::SDValue)' does not allow automatic multiple TOCs; recompile with -mminimal-toc or -fno-optimize-sibling-calls, or make `llvm::DAGTypeLegalizer::GetScalarizedVector(llvm::SDValue)' extern
Comment 11 Marcin Mirosław 2010-12-01 16:33:25 UTC
We have got clamav-0.96.5 ( http://git.clamav.net/gitweb?p=clamav-devel.git;a=blob_plain;f=ChangeLog;hb=clamav-0.96.5 ).
Comment 12 Brent Baude (RETIRED) gentoo-dev 2011-01-07 16:12:48 UTC
Updated toolchain fixed the TOC problem.  Marking stable ppc64
Comment 13 Tim Sammut (RETIRED) gentoo-dev 2011-01-07 16:20:41 UTC
Thanks, folks. GLSA request filed.
Comment 14 GLSAMaker/CVETool Bot gentoo-dev 2011-10-08 12:22:33 UTC
CVE-2010-3434 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3434):
  Buffer overflow in the find_stream_bounds function in pdf.c in libclamav in
  ClamAV before 0.96.3 allows remote attackers to cause a denial of service
  (application crash) or possibly execute arbitrary code via a crafted PDF
  document.  NOTE: some of these details are obtained from third party
  information.
Comment 15 Tim Sammut (RETIRED) gentoo-dev 2011-10-14 23:50:10 UTC
Rerating B1 since clamav often runs in automated systems where it simply scans all email processed, i.e. no user action is required to be exploited.
Comment 16 GLSAMaker/CVETool Bot gentoo-dev 2011-10-23 14:59:16 UTC
This issue was resolved and addressed in
 GLSA 201110-20 at http://security.gentoo.org/glsa/glsa-201110-20.xml
by GLSA coordinator Tim Sammut (underling).