Bug 13505

Summary: [CVE 21] clamav 0.103.3 CVEs found
Product: [ROSA-based products] ROSA Fresh Reporter: Yury <y.tumanov>
Component: System (kernel, glibc, systemd, bash, PAM...)Assignee: ROSA Linux Bugs <bugs>
Status: VERIFIED FIXED QA Contact: ROSA Linux Bugs <bugs>
Severity: critical    
Priority: High CC: a.proklov, e.kosachev, pastordidi, s.matveev, v.potapov, y.tumanov
Version: AllFlags: v.potapov: qa_verified+
y.tumanov: secteam_verified+
a.proklov: published+
Target Milestone: 2021.1 Fresh R12   
Hardware: All   
OS: Linux   
URL: CVE-2022-20698, CVE-2022-20785,
Whiteboard:
Platform: 2021.1 ROSA Vulnerability identifier:
RPM Package: ISO-related:
Bad POT generating: Upstream:

Description Yury 2023-08-24 00:18:24 MSK
Please patch CVEs for package clamav version 0.103.3
  
INFO (CVEs are): clamav 0.103.3
 cves found
CVE-2022-20698
Desc: A vulnerability in the OOXML parsing module in Clam AntiVirus (ClamAV) Software version 0.104.1 and LTS version 0.103.4 and prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper checks that may result in an invalid pointer read. An attacker could exploit this vulnerability by sending a crafted OOXML file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to crash, resulting in a denial of service condition.
Link: https://nvd.nist.gov/vuln/detail/CVE-2022-20698
Severity: HIGH
CVE-2022-20785
Desc: On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in HTML file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. For a description of this vulnerability, see the ClamAV blog. This advisory will be updated as additional information becomes available.
Link: https://nvd.nist.gov/vuln/detail/CVE-2022-20785
Severity: HIGH
Comment 1 Svyatoslav Matveev 2023-08-28 13:47:33 MSK
********** QA ADVISORY **********

CVE закрыто обновлением.

*** clamav
**  upd: 0.103.3 .. 0.103.8

https://abf.io/build_lists/4672577
https://abf.io/build_lists/4672576
https://abf.io/build_lists/4672575
https://abf.io/build_lists/4672579
https://abf.io/build_lists/4672578
Comment 2 Dmitry Postnikov 2023-08-28 18:42:09 MSK
***************************
The update sent to testings
Comment 3 Vladimir Potapov 2023-09-05 16:02:08 MSK
clamav-0.103.8-1
https://abf.io/build_lists/4672577
https://abf.io/build_lists/4672576
https://abf.io/build_lists/4672575
https://abf.io/build_lists/4672579
https://abf.io/build_lists/4672578
************************** Advisory **************************** 
upd: 0.103.3 .. 0.103.8, fix CVEs
****************************************************************
QA Verified
Comment 4 Yury 2023-10-18 17:53:13 MSK
secteam_verified
Comment 5 Yury 2023-10-18 17:58:20 MSK
secteam_verified