MGASA-2015-0190
Advisory lineage Upstream: 5 Downstream: 0
Published: 05 May 2015, 13:36
Last modified:16 Apr 2026, 06:25
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
05 May 2015, 13:36
Published
Vulnerability first disclosed
16 Apr 2026, 06:25
Last Modified
Vulnerability information updated
Description
Updated clamav packages fix security vulnerabilities This updates fixes the following security issues: Fix infinite loop condition on crafted y0da cryptor file. Identified and patch suggested by Sebastian Andrzej Siewior. CVE-2015-2221 Fix crash on crafted petite packed file. Reported and patch supplied by Sebastian Andrzej Siewior. CVE-2015-2222. Fix an infinite loop condition on a crafted "xz" archive file. This was reported by Dimitri Kirchner and Goulven Guiheux.CVE-2015-2668 Apply upstream patch for possible heap overflow in Henry Spencer's regex library. CVE-2015-2305 Fix crash in upx decoder with crafted file. Discovered and patch supplied by Sebastian Andrzej Siewior. CVE-2015-2170
Affected Systems
- mageia•clamav
< 0.98.7-1.mga4
References (7)
- https://advisories.mageia.org/MGASA-2015-0190.html
- https://bugs.mageia.org/show_bug.cgi?id=15792
- http://openwall.com/lists/oss-security/2015/05/03/1
- http://openwall.com/lists/oss-security/2015/05/03/2
- http://openwall.com/lists/oss-security/2015/05/03/3
- http://openwall.com/lists/oss-security/2015/05/03/4
- http://openwall.com/lists/oss-security/2015/05/03/5