==========================================================================
Ubuntu Security Notice USN-3722-6
September 18, 2018
clamav vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
– Ubuntu 12.04 ESM
Summary:
USN-3722-1 introduced a regression in ClamAV.
Software Description:
– clamav: Anti-virus utility for Unix
Details:
USN-3722-1 fixed vulnerabilities in ClamAV. The new package introduced
an issue which caused dpkg-reconfigure to enter an infinite loop. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that ClamAV incorrectly handled parsing certain HWP
files. A remote attacker could use this issue to cause ClamAV to hang,
resulting in a denial of service. (CVE-2018-0360)
It was discovered that ClamAV incorrectly handled parsing certain PDF
files. A remote attacker could use this issue to cause ClamAV to hang,
resulting in a denial of service. (CVE-2018-0361)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 ESM:
clamav 0.100.1+dfsg-1ubuntu0.12.04.4
In general, a standard system update will make all the necessary
changes.
References:
https://usn.ubuntu.com/usn/usn-3722-6
https://usn.ubuntu.com/usn/usn-3722-1
https://launchpad.net/bugs/1792051—–BEGIN PGP SIGNATURE—–
Version: GnuPG v2
iQIcBAABCAAGBQJboM2vAAoJEEW851uECx9pwGQP/0V8tTAZQOkCbnBtMUJongmd
M2ciqz9sRBgxgZCjkbVmO1H/zZ3uZGO1Xy9z68pHgB4BQoSe0Y01M9COOkM9Dcu5
THbVyn5zwmYNJ7pDfLyloLgyBdgdGiO1SfEs5mQrY0xUoleY4R+echdnKiroHgZ7
6b1dtr4EU4yyJbS5OLzOwwkeBBo6GZT7kGzYDNhuNXA0hdDjxWjuuC7ZZZFQC4Aq
ipcsNi1hTSwXRsNVBFx9PKct35PwmZzdoAc+Xy4OLwZayKti16Z3/NIT9CGTemuY
RiGQlWNgz7M43wUnhDOhOnwiPMpRnNtd0ojInl3VBOpbNWL/yG/DCZe6Ddl46Zxh
BGvDKtBe1mCu6l5nRHqWynoJijTVFC40Hvzm3uhX2eLUCR8zWlRgDsc7ChdbFzYI
nTN4+Gd7pATt+QIBWn4DoWXEjSjZTzngbAlJNzZDSYiYyNv1UJN3YLfTpCY2jQHU
Iq+UE6wZmz1Ro35SH/d/P6d3QpCUISW1j8r2PY28baLHauikNlr8ZDp7+LINr2SE
m977qnq1MtYUFmLnyXszDDaXkEcg2NjZ1tZkgJI1cMxSZxwG2PKOvIWrejYmMl70
zdDal5nBis22+a/WpFZEayviMRCCfWfjeTvsCfEIkrXi6lpJiZANz+Kf6lyx8eCo
nf1+EiNISV+4Neh7myIm
=I6sY
—–END PGP SIGNATURE—–
—