-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 03 Jul 2026 23:16:21 +0200 Source: clamav Architecture: source Version: 1.4.5+dfsg-1 Distribution: unstable Urgency: medium Maintainer: ClamAV Team <pkg-clamav-devel@lists.alioth.debian.org> Changed-By: Sebastian Andrzej Siewior <sebastian@breakpoint.cc> Closes: 1141303 1141347 Changes: clamav (1.4.5+dfsg-1) unstable; urgency=medium . * Import 1.4.5 (Closes: #1141303) - CVE-2026-20217 ("Fixed a bug in the PESpin unpacker cleanup path") - CVE-2026-20213 ("Fixed an integer overflow in PE rebuild size calculations") - CVE-2026-20216 ("Fixed an InstallShield archive extraction limit bypass") - CVE-2026-20214 ("Fixed an FSG unpacker loop underflow") - CVE-2026-20243 ("Fixed ALZ parser size handling bugs") - CVE-2026-20215 ("Fixed a 7z parser substream count overflow") - CVE-2026-20244 ("Fixed 32-bit DMG parser size checks") * Use -DCMAKE_BUILD_TYPE=RelWithDebInfo by default (Closes: #1141347). Checksums-Sha1: 6454e256ac5d4a36ccc43aaaec539f8c3181a2a6 3042 clamav_1.4.5+dfsg-1.dsc f35240155c184e0a514d6ae24e4d669cb60c9894 27685412 clamav_1.4.5+dfsg.orig.tar.xz d6bda30f4f78b769e6f65400ef5e528736d58ffa 521132 clamav_1.4.5+dfsg-1.debian.tar.xz Checksums-Sha256: cdb2309b27f674f6b9dea54e820f9232ba7318e1d00a5221e3f7e8030d3ce7ed 3042 clamav_1.4.5+dfsg-1.dsc 61eaa197005878dcdbe4a368c7c7255cd104228f79669f0a998717ab9a0dbf9c 27685412 clamav_1.4.5+dfsg.orig.tar.xz af5cd67159ab4512361ff02b3b714b5e98d1db252030d870415a1527ffb65071 521132 clamav_1.4.5+dfsg-1.debian.tar.xz Files: 0e311caa2a1f31e33ab27b701ebd3eb6 3042 utils optional clamav_1.4.5+dfsg-1.dsc ddae5dfa89a3f90e03f8fa3f92a09517 27685412 utils optional clamav_1.4.5+dfsg.orig.tar.xz c2cd2cf4f4838a202d3f8eae7f7401d9 521132 utils optional clamav_1.4.5+dfsg-1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQGzBAEBCgAdFiEEV4kucFIzBRM39v3RBWQfF1cS+lsFAmpIKHgACgkQBWQfF1cS +lvUgAv+N7NIwqc1NAqHet/3rIrJ2yJQKoe0pwDSFVvPt6urBVpqjMRsoNwXDdG6 ZDeCvFDcSXJNKjkN4WI9Om25z+aXRBeezPM+HCwStzVkdlJtz9PAOYzwYiMEISvd v1XgD+Es548croORclUd/LAQJrCUzGOFx6LfqPSEOz5DIqv5KtYiOhMGz1bpzsRA ItsRoRa2ocAtxQOT7qZe1Kc1C1mO5jG+y1l6D/Ft6f//cQzDPonF+juPxBms4oOM 7mmgscT/Jgn/E2V0R3Z9R/FUVuWX0nNpUig4e581D/+SwrffS91Eijgl11p/zjRO fGXUXQ5AlylK+T7rPcDqhWY7AE0ywCB0NMiTOsZWB8TS4E7XpEc+fpAilOcaWP0v qZHoafbqK3eKuTs2tQH7lVGbMCKh4Kv/xxEPcnOrY3q8Iz4hv7JbbDQY6Qq6QyBP EdS4+Sl2/WDcNjobyo9+Gtmh8ElopEM9cdGRZHmySSiowP0j4PDEPimxa11STx8+ A3kMr5KT =8jUW -----END PGP SIGNATURE-----