-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 25 Aug 2019 14:08:40 +0200 Source: clamav Architecture: source Version: 0.101.4+dfsg-0+deb9u1 Distribution: stretch Urgency: medium Maintainer: ClamAV Team <pkg-clamav-devel@lists.alioth.debian.org> Changed-By: Sebastian Andrzej Siewior <sebastian@breakpoint.cc> Closes: 921190 934359 Changes: clamav (0.101.4+dfsg-0+deb9u1) stretch; urgency=medium . * Import 0.101.4 (Closes: 921190) - CVE-2019-12625 (Add scan time limit to limit the processing zip-bombs) (Closes:934359) - CVE-2019-12900 (An out of bounds write was possible within ClamAV's NSIS bzip) - update symbols file (bump to 101.4 and drop unused cli_strnstr). Checksums-Sha1: 69d9c3bb793bb26f9c16b08a15cfc743ebb0372d 2889 clamav_0.101.4+dfsg-0+deb9u1.dsc ae609c30ebf523a2f5e1b5f3cf25332cbb48686d 4975416 clamav_0.101.4+dfsg.orig.tar.xz 7c614cbca89e6a7a92412e7ec71bdd56143f49d8 218824 clamav_0.101.4+dfsg-0+deb9u1.debian.tar.xz 4fe97c0ba8361fc4d3f1955b2871863d47b06602 6508 clamav_0.101.4+dfsg-0+deb9u1_source.buildinfo Checksums-Sha256: e83ab95832a72e2dee0e1e687d2e07cdf34cc84382d50f1501c8d88925e749f2 2889 clamav_0.101.4+dfsg-0+deb9u1.dsc f97e09180cf15391db8b5c9db18a1409b748a417861a6aa4621db8844dde3c23 4975416 clamav_0.101.4+dfsg.orig.tar.xz cd31b1fa022a1b6bf3d999451f89b47d5824ff808f5a390b3f7466210074bb0b 218824 clamav_0.101.4+dfsg-0+deb9u1.debian.tar.xz c6173dce621fe5c932f1241b3910cb75a73a614a86751765d8dd1a8e851a2018 6508 clamav_0.101.4+dfsg-0+deb9u1_source.buildinfo Files: ef28c57709b63882766dfcd67f5d5be6 2889 utils optional clamav_0.101.4+dfsg-0+deb9u1.dsc 915d7b2d6113055a31d8adcca1e0d0dd 4975416 utils optional clamav_0.101.4+dfsg.orig.tar.xz efaab28bd668ae55f4875b3dd285184d 218824 utils optional clamav_0.101.4+dfsg-0+deb9u1.debian.tar.xz fd5938bf6930ab3d04358730cf18ac57 6508 utils optional clamav_0.101.4+dfsg-0+deb9u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQGzBAEBCgAdFiEEV4kucFIzBRM39v3RBWQfF1cS+lsFAl1ii0AACgkQBWQfF1cS +lt4ggv/Rf0Z71NzGiqpHffXYeOhgY0X6WHRSLoxe42rLIMQzHvatyeDCuNH49jh 5Jupm8Bz6XU8pRPaicRFW/yMFTdKNT2ZtcX0TfHfRZuM03qQJqmbyNgPf8MYUruP OJZMBpAWgFEcUIauEYR2iQ6w8zXGvjlL9Z8l8UAa7A5lKSCdyCo78J3DcUMgMkJh qJX75s+uSYB4SflN2vLTTs0cT0IyOlo7Cd0cWEpJd5Ag/d7HEvSLVqoNa/7LI6Qj knWwcl9gbXpC3TLDr9mhq0BIlcjde5jPZD1Fc8rcS3HBKlQgXMX1z/0me/YrFlbx 0huerknt/xBn4Yrif5rG89qVehEsSYPgjukyZRIznuIIHf97cGXVkDZSceNK5nkV jWybiiliQBKAK32Did8f1kzn0RfdZxwB/TAttWAP1CEbdGlt/NzEWpv2oJJ/AsW1 Q7U7Nd2QcGECSWWq3v6URiMc0Dmkdtp6/iWTboiSBCRfRJejGUUZ94BkdNt+A9IB HwS1ZAoD =WqiB -----END PGP SIGNATURE-----