lp://staging/ubuntu/lucid-updates/clamav
- Get this branch:
- bzr branch lp://staging/ubuntu/lucid-updates/clamav
Branch merges
Branch information
Recent revisions
- 95. By chris pollock
-
[ Marc Deslauriers ]
* Updated to 0.98.6 to fix security issues, including CVE-2014-9328.
(LP: #1420819)
* Removed upstreamed patches:
- d/p/0002-Add-an- additional- n-after- the-number- in-the- pidfile. patch
- d/p/0017-Bump-.so- version- number. patch [ Chris Pollock ]
* Drop dh_autoreconf from build-depends
* Remove use of dh_autoreconf from debian/rules
* Adjust list of no LLVM architectures in debian/rules to include powerpc
to avoid FTBFS on lucid - 93. By Scott Kitterman
-
[ Seth Arnold ]
* SECURITY UPDATE: Updated to 0.97.8 to fix multiple security issues.
- CVE-2013-2020 and CVE-2013-2021[ Scott Kitterman ]
* Merge from Debian unstable (LP: #1172981). Remaining changes:
- Drop build-dep on electric-fence (in Universe)
- Add apparmor profiles for clamd and freshclam along with maintainer
script changes - 92. By Marc Deslauriers
-
* SECURITY UPDATE: Updated to 0.97.7 to fix multiple security issues.
(LP: #1157385)
- CVE numbers pending - 91. By Marc Deslauriers
-
* SECURITY UPDATE: fix detection bypass via malformed tar entry with
length that exceeds tar size
- libclamav/untar.c: scan output at end of truncated tar
- http://git.clamav. net/gitweb? p=clamav- devel.git; a=commit; h=8e199ae3cfb2b 862b8bc36d9a01c 8f8d716169ab
- CVE-2012-1457
* SECURITY UPDATE: fix detection bypass via crafted reset interval in
CHM file
- libclamav/mspack.c: properly scan chm with invalid handling.
- http://git.clamav. net/gitweb? p=clamav- devel.git; a=commit; h=a58b68f8adf24 66b761ce05f74a4 580c1f74fbe6
- http://git.clamav. net/gitweb? p=clamav- devel.git; a=commit; h=9d6be7c56091f 012e90074122db4 ec12d3516011
- CVE-2012-1458
* SECURITY UPDATE: fix detection bypass via tar archive with invalid
length field
- libclamav/untar.c: improve logic, look at checksums
- http://git.clamav. net/gitweb? p=clamav- devel.git; a=commit; h=c3c807d78b09b 3f64630601002fd c7db257d89da
- http://git.clamav. net/gitweb? p=clamav- devel.git; a=commit; h=9d6be7c56091f 012e90074122db4 ec12d3516011
- CVE-2012-1459 - 90. By Jamie Strandboge
-
* SECURITY UPDATE: fix recursion level crash
- libclamav/bytecode. c, libclamav/ bytecode_ api.c:adjust recursion level
before and after calling cli_magic_scandesc( )
- http://git.clamav. net/gitweb? p=clamav- devel.git; a=patch; h=3d664817f6ef8 33a17414a4ecea4 2004c35cc42f
- CVE-2011-3627 - 89. By Marc Deslauriers
-
* SECURITY UPDATE: denial of service via double free in vba processing
- libclamav/vba_extract. c: set buf to NULL when it gets freed.
- http://git.clamav. net/gitweb? p=clamav- devel.git; a=commit; h=d21fb8d975f8c 9688894a8cef4d5 0d977022e09f
- CVE-2011-1003 - 88. By Scott Kitterman
-
* Microversion update for Lucid (LP: #691414)
- Improved database login times
- Expanded use of new bytecode signatures
- Other bugfixes/improvements - 87. By Serge Hallyn
-
* SECURITY UPDATE: Backport security fixes from 0.96.5 (LP: #673654):
- (simple port from Scott Kitterman's debdiff for natty)
- libclamav/pdf.c: fix crashes
- http://git.clamav. net/gitweb? p=clamav- devel.git; a=commitdiff_ plain;h= 019f19551943606 00ecf0644959cec a6734c2d7b
- CVE-2010-4260, CVE-2010-4479
- libclamav/pe_icons. c: off by one
- http://git.clamav. net/gitweb? p=clamav- devel.git; a=commitdiff_ plain;h= 1f3db7f074995bd 4e1d0183b2db8b1 c472d2f41b
- CVE-2010-4261
Branch metadata
- Branch format:
- Branch format 7
- Repository format:
- Bazaar repository format 2a (needs bzr 1.16 or later)
- Stacked on:
- lp://staging/ubuntu/natty/clamav