package/clamav: security bump version to 0.102.2
authorBernd Kuhls <bernd.kuhls@t-online.de>
Thu, 6 Feb 2020 18:43:14 +0000 (19:43 +0100)
committerPeter Korsgaard <peter@korsgaard.com>
Thu, 6 Feb 2020 20:01:56 +0000 (21:01 +0100)
commit19748514b8907ff1dbc2d7cb6c02362927a238e1
tree0181ef2dfea7a6cd80c58978ccb3ff49067425ba
parent3091d334e740364e8a213d206896818e9b15255b
package/clamav: security bump version to 0.102.2

Fixes CVE-2020-3123: A vulnerability in the Data-Loss-Prevention (DLP)
module in Clam AntiVirus (ClamAV) Software versions 0.102.1 and 0.102.0
could allow an unauthenticated, remote attacker to cause a denial of service
condition on an affected device.  The vulnerability is due to an
out-of-bounds read affecting users that have enabled the optional DLP
feature.  An attacker could exploit this vulnerability by sending a crafted
email file to an affected device.  An exploit could allow the attacker to
cause the ClamAV scanning process crash, resulting in a denial of service
condition.

Release notes:
https://lists.clamav.net/pipermail/clamav-announce/2020/000045.html

Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/clamav/clamav.hash
package/clamav/clamav.mk