-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Fri, 29 Mar 2019 19:40:34 -0400 Source: clamav Binary: clamav-base clamav-docs clamav-dbg clamav libclamav-dev libclamav7 clamav-daemon clamdscan clamav-testfiles clamav-freshclam clamav-milter Architecture: source all amd64 Version: 0.100.3+dfsg-0+deb8u1 Distribution: jessie-security Urgency: medium Maintainer: ClamAV Team <pkg-clamav-devel@lists.alioth.debian.org> Changed-By: Ola Lundqvist <ola@inguza.com> Description: clamav - anti-virus utility for Unix - command-line interface clamav-base - anti-virus utility for Unix - base package clamav-daemon - anti-virus utility for Unix - scanner daemon clamav-dbg - debug symbols for ClamAV clamav-docs - anti-virus utility for Unix - documentation clamav-freshclam - anti-virus utility for Unix - virus database update utility clamav-milter - anti-virus utility for Unix - sendmail integration clamav-testfiles - anti-virus utility for Unix - test files clamdscan - anti-virus utility for Unix - scanner client libclamav-dev - anti-virus utility for Unix - development files libclamav7 - anti-virus utility for Unix - library Changes: clamav (0.100.3+dfsg-0+deb8u1) jessie-security; urgency=medium . * Non-maintainer upload by the LTS Team. * Upload based on the stretch package, thanks to: Scott Kitterman. The included parts from strech package are described below. * New upstream security release - Fixes for the following vulnerabilities: - [CVE-2019-1787]: An out-of-bounds heap read condition may occur when scanning PDF documents. The defect is a failure to correctly keep track of the number of bytes remaining in a buffer when indexing file data. - [CVE-2019-1789]: An out-of-bounds heap read condition may occur when scanning PE files (i.e. Windows EXE and DLL files) that have been packed using Aspack as a result of inadequate bound-checking. - [CVE-2019-1788]: An out-of-bounds heap write condition may occur when scanning OLE2 files such as Microsoft Office 97-2003 documents. The invalid write happens when an invalid pointer is mistakenly used to initialize a 32bit integer to zero. This is likely to crash the application. * Update debian/copyright to version from stretch. * Update private symbols for new upstream release to version from stretch. Checksums-Sha1: 02fb260c6f4bf78b7e0b224c1a180402a2fafb2e 3130 clamav_0.100.3+dfsg-0+deb8u1.dsc 09e24feb0291805fdf65719b64824d776fc6e9dd 9238759 clamav_0.100.3+dfsg.orig.tar.gz 0d3f486ff81beecc5873251cc0dbcc4cbff748d9 211360 clamav_0.100.3+dfsg-0+deb8u1.debian.tar.xz bfa6d07c40bac6cd941966ddb0da874eb613e51f 106520 clamav-base_0.100.3+dfsg-0+deb8u1_all.deb 38b41c94594dcec708efbf3b7954b7c4341f0acf 743020 clamav-docs_0.100.3+dfsg-0+deb8u1_all.deb 8fc2330ba098d37a437ce62f0e4e6785e91b9a4d 2450070 clamav-dbg_0.100.3+dfsg-0+deb8u1_amd64.deb 8eabff5fcd5511c37df58a79e1f31c477a7d4cb4 165710 clamav_0.100.3+dfsg-0+deb8u1_amd64.deb dbfc7c8a2c0001443d9c9c0c9d56528f7a708cdf 64212 libclamav-dev_0.100.3+dfsg-0+deb8u1_amd64.deb a41a83c6931078a51edb7c38c2407c6d497bbc35 827538 libclamav7_0.100.3+dfsg-0+deb8u1_amd64.deb 7433eaa3243dfcfd6577f35621946a211dedbe60 265356 clamav-daemon_0.100.3+dfsg-0+deb8u1_amd64.deb 8d16cd70690a307db7ccca91b7c299d31baf6485 124824 clamdscan_0.100.3+dfsg-0+deb8u1_amd64.deb a3a84d94b4fd172f2bc4c202ede674ad2b21ca7f 2881762 clamav-testfiles_0.100.3+dfsg-0+deb8u1_all.deb a382400c093b703cba6f56286805bbeb4baa1fe6 213322 clamav-freshclam_0.100.3+dfsg-0+deb8u1_amd64.deb 0f8224fae799b912c310be0f2b9c2acd0896cc05 256600 clamav-milter_0.100.3+dfsg-0+deb8u1_amd64.deb Checksums-Sha256: 6e87616aca1b5388e6b6d3a9a49ff9b0efd46aae0129e94631ac1f1edcf840da 3130 clamav_0.100.3+dfsg-0+deb8u1.dsc 9584784bfc285db7af2fd5348dc3f46137a8f7029f21578780403c5719fa4868 9238759 clamav_0.100.3+dfsg.orig.tar.gz cd9940c52d9477832830aa52e31eaab431150dec9d240bc0c100ea4e4af228d4 211360 clamav_0.100.3+dfsg-0+deb8u1.debian.tar.xz 970c6b7543aade8d2b9dcd29fbb51fae57c86499461417360b79426fd26c51a7 106520 clamav-base_0.100.3+dfsg-0+deb8u1_all.deb 2a359390e0d17bd6b46759c2d98071e907a740493611c757675936ee99e872ae 743020 clamav-docs_0.100.3+dfsg-0+deb8u1_all.deb bcafb43ef89d79cea22c8a36e89893e1cf7d96f09334e1a2ce7105c10bc58dd8 2450070 clamav-dbg_0.100.3+dfsg-0+deb8u1_amd64.deb 332c879124101a92853c5face07af6a977f8fc3ecd078a4c3bc32fbcd217feee 165710 clamav_0.100.3+dfsg-0+deb8u1_amd64.deb 8539e2c87acaff266bcbde75bfd508c544c512992a1b13cbe36cfb7266396f43 64212 libclamav-dev_0.100.3+dfsg-0+deb8u1_amd64.deb 2c47d2042fb4f86b79b988a8d35c45d04e8c34a52f0d16493924718a4605b958 827538 libclamav7_0.100.3+dfsg-0+deb8u1_amd64.deb 5cad4318c80ce55dc1562bbfa4d01a33cf92b41484d3e237d32f135dd70bee4a 265356 clamav-daemon_0.100.3+dfsg-0+deb8u1_amd64.deb b8abbea292ad6cd495b41d92e0e10c0003f20fbf9a64678715562fb18d990b06 124824 clamdscan_0.100.3+dfsg-0+deb8u1_amd64.deb 7be5bbd550b5f918370597551d57cb461364dfc375bd5c894c890db720d7bb1b 2881762 clamav-testfiles_0.100.3+dfsg-0+deb8u1_all.deb 5ffafe44e2191129acaf4be8dcafcd6def4e114192409c9ade84ff58c12b17a9 213322 clamav-freshclam_0.100.3+dfsg-0+deb8u1_amd64.deb 2b22dad8c8c428261fa7966aff0a18eedd96a56a7432f820701cbff300391afc 256600 clamav-milter_0.100.3+dfsg-0+deb8u1_amd64.deb Files: f9fe3fdf3282418bd6d8cb2aef3382fb 3130 utils optional clamav_0.100.3+dfsg-0+deb8u1.dsc 5476960b8bbb3ac3d4feb74509e143a3 9238759 utils optional clamav_0.100.3+dfsg.orig.tar.gz 9213e5042afc37ecaf00898c02749ec9 211360 utils optional clamav_0.100.3+dfsg-0+deb8u1.debian.tar.xz aa20fe401c7ab5eda192927f1c69d77b 106520 utils optional clamav-base_0.100.3+dfsg-0+deb8u1_all.deb c675350d84e5307614a4a52c12a3af0b 743020 doc optional clamav-docs_0.100.3+dfsg-0+deb8u1_all.deb 9a68ae478a6ff43b5a8f55f673cc27a1 2450070 debug extra clamav-dbg_0.100.3+dfsg-0+deb8u1_amd64.deb 153db0a075413d6d5a5f0ea8e14637db 165710 utils optional clamav_0.100.3+dfsg-0+deb8u1_amd64.deb 0bd0180573dac609ddb07bea4bdd61b5 64212 libdevel optional libclamav-dev_0.100.3+dfsg-0+deb8u1_amd64.deb 2880bbf3339d2249e832fa17607872f7 827538 libs optional libclamav7_0.100.3+dfsg-0+deb8u1_amd64.deb 5138abc73cc0e77083e3e90ff2f644d1 265356 utils optional clamav-daemon_0.100.3+dfsg-0+deb8u1_amd64.deb 8f1afbe10feb96e145f01dff1595e291 124824 utils optional clamdscan_0.100.3+dfsg-0+deb8u1_amd64.deb 6db4c7bf8de908a95ca457e3bc2c202a 2881762 utils optional clamav-testfiles_0.100.3+dfsg-0+deb8u1_all.deb 73ecab87f893e57f6946a2e8d989bacc 213322 utils optional clamav-freshclam_0.100.3+dfsg-0+deb8u1_amd64.deb e8a3c2c50b4f4aaf5f7053cb5edecafd 256600 utils extra clamav-milter_0.100.3+dfsg-0+deb8u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEIvIyxrHg9L8rJgpqXpDc+pQmh28FAly9nWAACgkQXpDc+pQm h28NTg//Te8Asu/uYEuNkA8EtbCk/7Gl0phMTHLXGYKx5rB8x1vGqAaVI6nFsTvR 3uwFFXjJgf40FIPbUTcvQUPalIMhJxXK4hwfcC93BkpojrHZoiFW2hzk9E3qr4dS dE60f3jn5FWhHeqy5ii2/g49GNgfKOP6rvkUPC2r9nD2tTnWRI24JwQ+iioP5eHZ l1rG0rYDEQAtxruzqFmcLWMfw5IAyJzumcujrCa2rapIYEJATlWbMyFdmADOpIyX mI8M3jiT4Kw1j6EKwCn7dkIcnEkGWyfIVtsKz58YeMJ3icGMgAkn/e12TUbv4zVc 2yfzXnJOA/quBDEJCKGKyuFvXTq6ThMpgH8lpwnyOnL5TBicxPH2OnZlQUajtrWK XNuvyKWM4I0v+UX49Rb0YmSxV1x0WKRQFd7veqIIOQ55TnOxKal51+sDj2X9EDkG 8+ES804Z7I7dyvQbxLM7Vr0ifXP7ZfA+JV3uQxluNSE3PfIR62Xv2cQTLxnX6CIK Cn9/1DmGJvOLQ1sfQGOlez95JlxoETK+lv0ri6DL0OCgmGXpRm3icp8vAwFC1SmK yzs1ZSnZ0wd+WmDE1hHSJ8EUGIHtpi/8KyKEYZndmM/kSkp90wCNGNZjMaSE5BxJ V5bByRwifQgkINGVtxXHGhPA8vwdGWmzhOACFgWlqSXpxurvdiM= =N0vO -----END PGP SIGNATURE-----