First published: Thu May 21 2020(Updated: )
USN-4370-1 fixed several vulnerabilities in ClamAV. This update provides the corresponding update for Ubuntu 12.04 ESM and 14.04 ESM. Original advisory details: It was discovered that ClamAV incorrectly handled parsing ARJ archives. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2020-3327) It was discovered that ClamAV incorrectly handled parsing PDF files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2020-3341)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/clamav | <0.102.3+dfsg-0ubuntu0.14.04.1+esm1 | 0.102.3+dfsg-0ubuntu0.14.04.1+esm1 |
Ubuntu Ubuntu | =14.04 | |
All of | ||
ubuntu/clamav | <0.102.3+dfsg-0ubuntu0.12.04.1 | 0.102.3+dfsg-0ubuntu0.12.04.1 |
Ubuntu Ubuntu | =12.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-4370-2 is not specified.
USN-4370-2 fixes vulnerabilities in ClamAV related to parsing ARJ archives.
To fix the vulnerabilities addressed by USN-4370-2, you should update ClamAV to version 0.102.3+dfsg-0ubuntu0.14.04.1+esm1 for Ubuntu 14.04 or version 0.102.3+dfsg-0ubuntu0.12.04.1 for Ubuntu 12.04.
More information about CVE-2020-3327 can be found at the following link: https://ubuntu.com/security/CVE-2020-3327
More information about CVE-2020-3341 can be found at the following link: https://ubuntu.com/security/CVE-2020-3341