vulnerability

FreeBSD: VID-dbd1f627-c43b-11e9-a923-9c5c8e75236a (CVE-2019-12900): clamav -- multiple vulnerabilities

Severity
7
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
Aug 21, 2019
Added
Aug 21, 2019
Modified
Dec 10, 2025

Description

Micah Snyder reports: An out of bounds write was possible within ClamAV&s NSIS bzip2 library when attempting decompression in cases where the number of selectors exceeded the max limit set by the library (CVE-2019-12900). The issue has been resolved by respecting that limit. The zip bomb vulnerability mitigated in 0.101.3 has been assigned the CVE identifier CVE-2019-12625. Unfortunately, a workaround for the zip-bomb mitigation was immediately identified. To remediate the zip-bomb scan time issue, a scan time limit has been introduced in 0.101.4. This limit now resolves ClamAV's vulnerability to CVE-2019-12625.

Solutions

freebsd-upgrade-package-clamavfreebsd-upgrade-package-clamav-milterfreebsd-upgrade-package-bzip2
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.