-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Fri, 29 Mar 2019 19:40:34 -0400 Source: clamav Binary: clamav-base clamav-docs clamav libclamav-dev libclamav7 clamav-daemon clamdscan clamav-testfiles clamav-freshclam clamav-milter Architecture: source all amd64 Version: 0.100.3+dfsg-0+deb9u1 Distribution: stretch Urgency: medium Maintainer: ClamAV Team Changed-By: Scott Kitterman Description: clamav - anti-virus utility for Unix - command-line interface clamav-base - anti-virus utility for Unix - base package clamav-daemon - anti-virus utility for Unix - scanner daemon clamav-docs - anti-virus utility for Unix - documentation clamav-freshclam - anti-virus utility for Unix - virus database update utility clamav-milter - anti-virus utility for Unix - sendmail integration clamav-testfiles - anti-virus utility for Unix - test files clamdscan - anti-virus utility for Unix - scanner client libclamav-dev - anti-virus utility for Unix - development files libclamav7 - anti-virus utility for Unix - library Changes: clamav (0.100.3+dfsg-0+deb9u1) stretch; urgency=medium . * New upstream security release - Fixes for the following vulnerabilities: - [CVE-2019-1787]: An out-of-bounds heap read condition may occur when scanning PDF documents. The defect is a failure to correctly keep track of the number of bytes remaining in a buffer when indexing file data. - [CVE-2019-1789]: An out-of-bounds heap read condition may occur when scanning PE files (i.e. Windows EXE and DLL files) that have been packed using Aspack as a result of inadequate bound-checking. - [CVE-2019-1788]: An out-of-bounds heap write condition may occur when scanning OLE2 files such as Microsoft Office 97-2003 documents. The invalid write happens when an invalid pointer is mistakenly used to initialize a 32bit integer to zero. This is likely to crash the application. * Update debian/copyright * Update private symbols for new upstream release Checksums-Sha1: f57397224c8f6ba0abb8e3aecf33e04a78a07eb2 3053 clamav_0.100.3+dfsg-0+deb9u1.dsc 09e24feb0291805fdf65719b64824d776fc6e9dd 9238759 clamav_0.100.3+dfsg.orig.tar.gz 5566a0eb9eb50910e54292dc0b98e1b0ac2bec91 218412 clamav_0.100.3+dfsg-0+deb9u1.debian.tar.xz 6342934fff88bc12a8fc531e9558540abb321bb5 107298 clamav-base_0.100.3+dfsg-0+deb9u1_all.deb f489f0190152c42673ab74170f8133465c9e355d 377242 clamav-daemon-dbgsym_0.100.3+dfsg-0+deb9u1_amd64.deb f10057a8b3cc8985ac4d02e4b060c31a9d79a660 253398 clamav-daemon_0.100.3+dfsg-0+deb9u1_amd64.deb d13e8d5dc239756bf13918c4115846494eeafe00 287828 clamav-dbgsym_0.100.3+dfsg-0+deb9u1_amd64.deb d34b84fd0fe0f840394c33657571a71e3e4b981c 743164 clamav-docs_0.100.3+dfsg-0+deb9u1_all.deb 6f0de328d1286f5ae4d3a40fcb513370a354755e 131574 clamav-freshclam-dbgsym_0.100.3+dfsg-0+deb9u1_amd64.deb f509334535584dcf27c1dda0ea59d39423d56b4d 207864 clamav-freshclam_0.100.3+dfsg-0+deb9u1_amd64.deb 5e1926525abc4aa46edc97b6b0cfa7214e46c2e6 171548 clamav-milter-dbgsym_0.100.3+dfsg-0+deb9u1_amd64.deb 39398bfaea66514303a699c1aa9082fe6c3a6510 246752 clamav-milter_0.100.3+dfsg-0+deb9u1_amd64.deb e57997447f975a53e35a0801720c06bbf56f9a8a 2883416 clamav-testfiles_0.100.3+dfsg-0+deb9u1_all.deb 0e4e77a8c21f96f983ac68fb3439151b72c60f55 11955 clamav_0.100.3+dfsg-0+deb9u1_amd64.buildinfo 712184ed76a6f382af10191c0053a42cd8217a35 165090 clamav_0.100.3+dfsg-0+deb9u1_amd64.deb 3866be8dc4f94511b308bf5cc5faaf7afaeb585a 161544 clamdscan-dbgsym_0.100.3+dfsg-0+deb9u1_amd64.deb 4554bde47f11bd6e927ab001c7a39fd3ef43875b 125800 clamdscan_0.100.3+dfsg-0+deb9u1_amd64.deb b9877d49e963ec5bae218837b7257503fbf86fdf 65246 libclamav-dev_0.100.3+dfsg-0+deb9u1_amd64.deb 6d60fbad89523058735d5855d0650d4d4c71a8f2 2292278 libclamav7-dbgsym_0.100.3+dfsg-0+deb9u1_amd64.deb c1f535367d7754efc5a712a3fadbceda2421d06f 800492 libclamav7_0.100.3+dfsg-0+deb9u1_amd64.deb Checksums-Sha256: dbbf26df6b85187243155fb335095796cb6364267e5f6166123bd77c31749961 3053 clamav_0.100.3+dfsg-0+deb9u1.dsc 9584784bfc285db7af2fd5348dc3f46137a8f7029f21578780403c5719fa4868 9238759 clamav_0.100.3+dfsg.orig.tar.gz 0c5a7a63fbcce8fad4dab9f7fed94ac4c8b53a4ba5991c58dfdae2f6afbbfae8 218412 clamav_0.100.3+dfsg-0+deb9u1.debian.tar.xz 4e16e8a1fe65e69b5d8da246ec0588ff826a07d037ae2b2d97eb456a092bcfa7 107298 clamav-base_0.100.3+dfsg-0+deb9u1_all.deb de78790602c8309400779a91a6ab02c42b897056247acbc135d94f1eef121279 377242 clamav-daemon-dbgsym_0.100.3+dfsg-0+deb9u1_amd64.deb 3629f151edbc5b3d040c710386bed5afabeb9ba9ad38627040e42dfb0a0c9c1b 253398 clamav-daemon_0.100.3+dfsg-0+deb9u1_amd64.deb 878527553aa760d900122bfed6eebcb70bf6107b78bac1c49bcdb117e60cc21b 287828 clamav-dbgsym_0.100.3+dfsg-0+deb9u1_amd64.deb 305bc1123f41e138ddeea32e1b41fca5908f3468576379323c64332ec64c9409 743164 clamav-docs_0.100.3+dfsg-0+deb9u1_all.deb 984a06e9c35d11c10e54c24e2bbbb279ff00d473abdca904da718effe4a6d5e1 131574 clamav-freshclam-dbgsym_0.100.3+dfsg-0+deb9u1_amd64.deb 9d2a09b90c7c8f9b10380e0168bbdd71f01748daedd3cd1a37ec1fbe22b3c236 207864 clamav-freshclam_0.100.3+dfsg-0+deb9u1_amd64.deb 1bc04d5b13268cea0e20323b2cb42603610e122a504ad7fdfc3c6a627f690d52 171548 clamav-milter-dbgsym_0.100.3+dfsg-0+deb9u1_amd64.deb ddaa22ad3cce6d0c47e4a6d912229d3ff67b00294d93962217502f5a664b79b1 246752 clamav-milter_0.100.3+dfsg-0+deb9u1_amd64.deb 43d82c2e93a58b9fdc3fafff2078ac1ec8e8e924e0d4d70b0308895ae5c2d6fc 2883416 clamav-testfiles_0.100.3+dfsg-0+deb9u1_all.deb 54858ad2d02a3dfb6f13167bba4219d97a5b7b761739abc5619e5efa3a20aeeb 11955 clamav_0.100.3+dfsg-0+deb9u1_amd64.buildinfo 5f4613a418f2f97d60179931117ff0ad6b9323b1b95bce190fdd6d58fff1f2f9 165090 clamav_0.100.3+dfsg-0+deb9u1_amd64.deb dc52f7e2b2ff01b0df0f3235838bdad17adeeb5091c2e720025fce24050cf0d5 161544 clamdscan-dbgsym_0.100.3+dfsg-0+deb9u1_amd64.deb 567ff19d610ab448b643c9eda853837d3048cc4c033f1b5ba94ddf1b61cae591 125800 clamdscan_0.100.3+dfsg-0+deb9u1_amd64.deb 2aa5a984f70eb09a428930c0bec8ab6c1646e9d841c9f83dd7a9f3845121bbbb 65246 libclamav-dev_0.100.3+dfsg-0+deb9u1_amd64.deb d0adeac9008f765bf61853daaa7234baf29ce414c0bff5eb778c1de7c1aa1e0f 2292278 libclamav7-dbgsym_0.100.3+dfsg-0+deb9u1_amd64.deb 3eca3422aaeca82c4fc6f403e8d0f0414cbd79d92720248299fefc21dbe83d86 800492 libclamav7_0.100.3+dfsg-0+deb9u1_amd64.deb Files: 05c29a28133f5d6ba26ce03b12d15f8a 3053 utils optional clamav_0.100.3+dfsg-0+deb9u1.dsc 5476960b8bbb3ac3d4feb74509e143a3 9238759 utils optional clamav_0.100.3+dfsg.orig.tar.gz 9e68ed09d10c6d248169575bfbe91f89 218412 utils optional clamav_0.100.3+dfsg-0+deb9u1.debian.tar.xz 6e1af340f1ac47cea7a59acfb7c7eb4e 107298 utils optional clamav-base_0.100.3+dfsg-0+deb9u1_all.deb 248008ca2705f8a6ee408ac39db15c6e 377242 debug extra clamav-daemon-dbgsym_0.100.3+dfsg-0+deb9u1_amd64.deb 1d4222cc6b3d3a9a17538ff34bf685fb 253398 utils optional clamav-daemon_0.100.3+dfsg-0+deb9u1_amd64.deb e7c59d1c25c6ecf02d45b7d9f3aa5d9f 287828 debug extra clamav-dbgsym_0.100.3+dfsg-0+deb9u1_amd64.deb 1d617a628a2d31e44afdf54add5d6317 743164 doc optional clamav-docs_0.100.3+dfsg-0+deb9u1_all.deb 3980bd7261de730d78b87f74e07ff328 131574 debug extra clamav-freshclam-dbgsym_0.100.3+dfsg-0+deb9u1_amd64.deb 0e766dc4b06144614ac15c4c459699d5 207864 utils optional clamav-freshclam_0.100.3+dfsg-0+deb9u1_amd64.deb 01c85d42f47f454ad3e2adf69e9f383f 171548 debug extra clamav-milter-dbgsym_0.100.3+dfsg-0+deb9u1_amd64.deb 1795c63df166510ba861ffe7c43b9b42 246752 utils extra clamav-milter_0.100.3+dfsg-0+deb9u1_amd64.deb 53714dafbbe0ea2b26d75aa6e1d88c33 2883416 utils optional clamav-testfiles_0.100.3+dfsg-0+deb9u1_all.deb 5bc8623f7bea616b7dfd1ca13f032441 11955 utils optional clamav_0.100.3+dfsg-0+deb9u1_amd64.buildinfo ff078d5884432d35c207db604e98a027 165090 utils optional clamav_0.100.3+dfsg-0+deb9u1_amd64.deb a02b6e0080b7e07237811ed8050d7f4f 161544 debug extra clamdscan-dbgsym_0.100.3+dfsg-0+deb9u1_amd64.deb 848f1985bb4d48bd67059b606218e6f8 125800 utils optional clamdscan_0.100.3+dfsg-0+deb9u1_amd64.deb be7c7fb2a0525ba50cc4d2432b913e39 65246 libdevel optional libclamav-dev_0.100.3+dfsg-0+deb9u1_amd64.deb a54aa49d9f91ab541b638d952c086dac 2292278 debug extra libclamav7-dbgsym_0.100.3+dfsg-0+deb9u1_amd64.deb 4dcfb47d1be9620df7b45c6aad9537a6 800492 libs optional libclamav7_0.100.3+dfsg-0+deb9u1_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJcnyKZAAoJEHjX3vua1ZrxZ4UP/j/e/yjsc08m4Z3jK4siwnLt eidi4jTFF04tig6rC0LYjMUb/F2engfKULUFLhgk6cYSljy3aEcWJYg+J8tm3GZJ JdWJ/LX3mdGWNNV+P6ivjKQU5dYdC17rNbQZCPkD56Fewl2oWo2l63+aHjWjoFqh 8LHwGIIFr/ybYkgUeikedcwANIg4qa3jRjoud8PzaaA1nm8Oqkwi5EH8EMPoObWd yxZa9CsGFe82YSyavfP+IW1do74osA7uSyq6oP3AdoPv+ENaAHzY3B4tYY2662wY FHH4MUcwqCtLw56NpgzJEcOtm5d+kRQGHKitw4gltDTISQRlzy+pxJ2adGMfAlCA im4TAsM1TDlu84T9TusWBIu1izLDkJUg/7ZmE+D/s1bgIyOnHBZ2drnrrbmE19m/ qj+5SfzFu7qx0pZP4Yftv/TewEtMcFWiS/WRc8wLa6H0ppxDx2RWUnO06/3oZoU7 WsrW8N/df7MRHKGS5FnSaZgG5Z5edY5OqHhEPza9K+tACyzHqluQRW5YOQ9nuTk/ 7QqMz4dAlt8t1fK2Px2ep41tJ4bYGZ7cwO7g1dgl05x/ZKMUQYbrfblbpzHSfR1y us2iPOwVRQwiWjNm2wuAWlZ28kHxhAK1ik48fR/sbJm6QzZSJZSHb4ih7ASir4XH ycu3VOs53PrOYCLVPTpY =fJjI -----END PGP SIGNATURE-----