New Debian clamav 1.0.9+dfsg-1~deb12u1A~5.2.3.202509101046 fixes: This update addresses the following issues: 1.0.9+dfsg-1~deb12u1 (Sun, 29 Jun 2025 21:57:41 +0200) * Import 1.0.9 - CVE-2025-20128 (Fixed a possible buffer overflow read bug in the OLE2 file parser that could cause a denial-of-service (DoS) condition) - CVE-2025-20260 (Fixed a possible buffer overflow write bug in the PDF file parser that could cause a denial-of-service (DoS) condition or enable remote code execution.)
--- mirror/ftp/pool/main/c/clamav/clamav_1.0.7+dfsg-1~deb12u1A~5.2.0.202411191503.dsc +++ apt/ucs_5.2-0-errata5.2-3/source/clamav_1.0.9+dfsg-1~deb12u1A~5.2.3.202509101046.dsc @@ -1,7 +1,17 @@ -1.0.7+dfsg-1~deb12u1A~5.2.0.202411191503 [Tue, 19 Nov 2024 15:04:32 -0000] Univention builddaemon <buildd@univention.de>: +1.0.9+dfsg-1~deb12u1A~5.2.3.202509101046 [Wed, 10 Sep 2025 10:46:54 -0000] Univention builddaemon <buildd@univention.de>: * UCS auto build. The following patches have been applied to the original source package 030-silence-version-msg.quilt + +1.0.9+dfsg-1~deb12u1 [Sun, 29 Jun 2025 21:57:41 +0200] Sebastian Andrzej Siewior <sebastian@breakpoint.cc>: + + * Import 1.0.9 + - CVE-2025-20128 (Fixed a possible buffer overflow read bug in the OLE2 + file parser that could cause a denial-of-service (DoS) condition) + Closes: #1093880 + - CVE-2025-20260 (Fixed a possible buffer overflow write bug in the PDF + file parser that could cause a denial-of-service (DoS) condition or + enable remote code execution.) Closes: #1108046 1.0.7+dfsg-1~deb12u1 [Thu, 03 Oct 2024 11:57:45 +0200] Sebastian Andrzej Siewior <sebastian@breakpoint.cc>: <http://piuparts.knut.univention.de/5.2-3/#598448119794565589>
OK: YAML OK: Tests OK: piuparts
<https://errata.software-univention.de/#/?erratum=5.2x185>