26 Jul 10:54
[VUA 33-1] Updated clamav package fixes security flaw
Martin Zobel-Helas <zobel <at> ftbfs.de>
2007-07-26 08:54:35 GMT
2007-07-26 08:54:35 GMT
--------------------------------------------------------------------------- Debian Volatile Update Announcement VUA 33-1 http://volatile.debian.org debian-volatile <at> lists.debian.org Stephen Gran July 26, 2007 Martin Zobel-Helas --------------------------------------------------------------------------- Package : clamav Version : 0.91.1-0volatile1 and 0.91.1-1~volatile1 Importance : high CVE IDs : CVE-2007-3725 The following security flaw was found and fixed in clamav: [CVE-2007-2650]: Null pointer dereference in the unrar VM, causing a DoS. For sarge, an updated clamav package is available in sarge/volatile as version 0.91.1-0volatile1. For etch, an updated clamav package is available in etch/volatile as version 0.91.1-1~volatile1. We recommend that you update your system. This advisory was sent out without builds for arm and s390 architectures being available for etch/volatile. and without builds for arm, hppa, m68k, mips, mipsel and sparc being available for sarge/volatile. They will be released as soon as they are available. Upgrade Instructions(Continue reading)
RSS Feed