SUSE-SU-2025:0327-1

Source
https://www.suse.com/support/update/announcement/2025/suse-su-20250327-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:0327-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2025:0327-1
Upstream
CVE (6)
Related
Published
2025-02-03T09:39:39Z
Modified
2026-03-11T07:30:12Z
Summary
Security update for clamav
Details

This update for clamav fixes the following issues:

New version 1.4.2:

  • CVE-2025-20128, bsc#1236307: Fixed a possible buffer overflow read bug in the OLE2 file parser that could cause a denial-of-service (DoS) condition.
  • Start clamonacc with --fdpass to avoid errors due to clamd not being able to access user files. (bsc#1232242)

  • New version 1.4.1:

  • New version 1.4.0:

    • Added support for extracting ALZ archives.
    • Added support for extracting LHA/LZH archives.
    • Added the ability to disable image fuzzy hashing, if needed. For context, image fuzzy hashing is a detection mechanism useful for identifying malware by matching images included with the malware or phishing email/document.
    • https://blog.clamav.net/2024/08/clamav-140-feature-release-and-clamav.html
  • New version 1.3.2:

    • CVE-2024-20506: Changed the logging module to disable following symlinks on Linux and Unix systems so as to prevent an attacker with existing access to the 'clamd' or 'freshclam' services from using a symlink to corrupt system files.
    • CVE-2024-20505: Fixed a possible out-of-bounds read bug in the PDF file parser that could cause a denial-of-service condition.
    • Removed unused Python modules from freshclam tests including deprecated 'cgi' module that is expected to cause test failures in Python 3.13.
    • Fix unit test caused by expiring signing certificate.
    • Fixed a build issue on Windows with newer versions of Rust. Also upgraded GitHub Actions imports to fix CI failures.
    • Fixed an unaligned pointer dereference issue on select architectures.
    • Fixes to Jenkins CI pipeline.
  • New Version: 1.3.1:

    • CVE-2024-20380: Fixed a possible crash in the HTML file parser that could cause a denial-of-service (DoS) condition.
    • Updated select Rust dependencies to the latest versions.
    • Fixed a bug causing some text to be truncated when converting from UTF-16.
    • Fixed assorted complaints identified by Coverity static analysis.
    • Fixed a bug causing CVDs downloaded by the DatabaseCustomURL
    • Added the new 'valhalla' database name to the list of optional databases in preparation for future work.
  • New version: 1.3.0:

    • Added support for extracting and scanning attachments found in Microsoft OneNote section files. OneNote parsing will be enabled by default, but may be optionally disabled.
    • Added file type recognition for compiled Python ('.pyc') files.
    • Improved support for decrypting PDFs with empty passwords.
    • Fixed a warning when scanning some HTML files.
    • ClamOnAcc: Fixed an infinite loop when a watched directory does not exist.
    • ClamOnAcc: Fixed an infinite loop when a file has been deleted before a scan.
  • New version: 1.2.0:

    • Added support for extracting Universal Disk Format (UDF) partitions.
    • Added an option to customize the size of ClamAV's clean file cache.
    • Raised the MaxScanSize limit so the total amount of data scanned when scanning a file or archive may exceed 4 gigabytes.
    • Added ability for Freshclam to use a client certificate PEM file and a private key PEM file for authentication to a private mirror.
    • Fix an issue extracting files from ISO9660 partitions where the files are listed in the plain ISO tree and there also exists an empty Joliet tree.
    • PID and socket are now located under /run/clamav/clamd.pid and /run/clamav/clamd.sock .
    • bsc#1211594: Fixed an issue where ClamAV does not abort the signature load process after partially loading an invalid signature.
  • New version 1.1.0:

References

Affected packages

SUSE:Linux Enterprise Module for Basesystem 15 SP6 / clamav

Package

Name
clamav
Purl
pkg:rpm/suse/clamav&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.4.2-150600.18.6.1

Ecosystem specific

{
    "binaries":  [
        {
            "clamav":  "1.4.2-150600.18.6.1",
            "clamav-devel":  "1.4.2-150600.18.6.1",
            "clamav-docs-html":  "1.4.2-150600.18.6.1",
            "clamav-milter":  "1.4.2-150600.18.6.1",
            "libclamav12":  "1.4.2-150600.18.6.1",
            "libclammspack0":  "1.4.2-150600.18.6.1",
            "libfreshclam3":  "1.4.2-150600.18.6.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:0327-1.json"

openSUSE:Leap 15.6 / clamav

Package

Name
clamav
Purl
pkg:rpm/opensuse/clamav&distro=openSUSE%20Leap%2015.6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.4.2-150600.18.6.1

Ecosystem specific

{
    "binaries":  [
        {
            "clamav":  "1.4.2-150600.18.6.1",
            "clamav-devel":  "1.4.2-150600.18.6.1",
            "clamav-docs-html":  "1.4.2-150600.18.6.1",
            "clamav-milter":  "1.4.2-150600.18.6.1",
            "libclamav12":  "1.4.2-150600.18.6.1",
            "libclammspack0":  "1.4.2-150600.18.6.1",
            "libfreshclam3":  "1.4.2-150600.18.6.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:0327-1.json"