ELA-937-1 clamav security update

dos; new upstream version

2023-08-28
Packageclamav
Version0.103.9+dfsg-0+deb8u1 (jessie), 0.103.9+dfsg-0+deb9u1 (stretch)
Related CVEs CVE-2023-20197


A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV, an anti-virus utility for Unix, could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.



For Debian 8 jessie, these problems have been fixed in version 0.103.9+dfsg-0+deb8u1.

For Debian 9 stretch, these problems have been fixed in version 0.103.9+dfsg-0+deb9u1.

We recommend that you upgrade your clamav packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.