USN-4066-2: ClamAV vulnerability
22 July 2019
ClamAV could be made to expose sensitive information if it received a specially crafted CHM file.
Releases
Packages
- clamav - Anti-virus utility for Unix
Details
USN-4066-1 fixed a vulnerability in libmspack. This update provides
the corresponding update for ClamAV in Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that ClamAV incorrectly handled certain CHM files.
A remote attacker could possibly use this issue to access sensitive information.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 14.04
Ubuntu 12.04
In general, a standard system update will make all the necessary changes.
References
Related notices
- USN-4066-1: libmspack-dev, libmspack-doc, libmspack0, libmspack