<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">clamav-0.103.8-1.1 on GA media</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2024:12696</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2024-06-17T21:45:33Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2024-06-17T21:45:33Z</InitialReleaseDate>
    <CurrentReleaseDate>2024-06-17T21:45:33Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">clamav-0.103.8-1.1 on GA media</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">These are all security issues fixed in the clamav-0.103.8-1.1 package on the GA media of openSUSE Tumbleweed.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-Tumbleweed-2024-12696</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL/>
      <Description>E-Mail link for openSUSE-SU-2024:12696</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-20032/</URL>
      <Description>SUSE CVE CVE-2023-20032 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-20052/</URL>
      <Description>SUSE CVE CVE-2023-20052 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Tumbleweed">
      <Branch Type="Product Name" Name="openSUSE Tumbleweed">
        <FullProductName ProductID="openSUSE Tumbleweed" CPE="cpe:/o:opensuse:tumbleweed">openSUSE Tumbleweed</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="clamav-0.103.8-1.1">
      <FullProductName ProductID="clamav-0.103.8-1.1">clamav-0.103.8-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="clamav-devel-0.103.8-1.1">
      <FullProductName ProductID="clamav-devel-0.103.8-1.1">clamav-devel-0.103.8-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="clamav-docs-html-0.103.8-1.1">
      <FullProductName ProductID="clamav-docs-html-0.103.8-1.1">clamav-docs-html-0.103.8-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="clamav-milter-0.103.8-1.1">
      <FullProductName ProductID="clamav-milter-0.103.8-1.1">clamav-milter-0.103.8-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libclamav9-0.103.8-1.1">
      <FullProductName ProductID="libclamav9-0.103.8-1.1">libclamav9-0.103.8-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libfreshclam2-0.103.8-1.1">
      <FullProductName ProductID="libfreshclam2-0.103.8-1.1">libfreshclam2-0.103.8-1.1</FullProductName>
    </Branch>
    <Relationship ProductReference="clamav-0.103.8-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:clamav-0.103.8-1.1">clamav-0.103.8-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="clamav-devel-0.103.8-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:clamav-devel-0.103.8-1.1">clamav-devel-0.103.8-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="clamav-docs-html-0.103.8-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:clamav-docs-html-0.103.8-1.1">clamav-docs-html-0.103.8-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="clamav-milter-0.103.8-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:clamav-milter-0.103.8-1.1">clamav-milter-0.103.8-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libclamav9-0.103.8-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libclamav9-0.103.8-1.1">libclamav9-0.103.8-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libfreshclam2-0.103.8-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libfreshclam2-0.103.8-1.1">libfreshclam2-0.103.8-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed:

 
 A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to execute arbitrary code.

 
 This vulnerability is due to a missing buffer size check that may result in a heap buffer overflow write. An attacker could exploit this vulnerability by submitting a crafted HFS+ partition file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to execute arbitrary code with the privileges of the ClamAV scanning process, or else crash the process, resulting in a denial of service (DoS) condition.

 For a description of this vulnerability, see the ClamAV blog ["https://blog.clamav.net/"].</Note>
    </Notes>
    <CVE>CVE-2023-20032</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:clamav-0.103.8-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:clamav-devel-0.103.8-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:clamav-docs-html-0.103.8-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:clamav-milter-0.103.8-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libclamav9-0.103.8-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libfreshclam2-0.103.8-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-20032.html</URL>
        <Description>CVE-2023-20032</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1208363</URL>
        <Description>SUSE Bug 1208363</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1211720</URL>
        <Description>SUSE Bug 1211720</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed:

 
 A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to access sensitive information on an affected device.

 
 This vulnerability is due to enabling XML entity substitution that may result in XML external entity injection. An attacker could exploit this vulnerability by submitting a crafted DMG file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to leak bytes from any file that may be read by the ClamAV scanning process.</Note>
    </Notes>
    <CVE>CVE-2023-20052</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:clamav-0.103.8-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:clamav-devel-0.103.8-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:clamav-docs-html-0.103.8-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:clamav-milter-0.103.8-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libclamav9-0.103.8-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libfreshclam2-0.103.8-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-20052.html</URL>
        <Description>CVE-2023-20052</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1208365</URL>
        <Description>SUSE Bug 1208365</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
