VDB

GCVE-110-MAGEIA-2019-328

GCVE-110-MAGEIA-2019-328
Advisory Published
Vulnetix · Advisory published November 19, 2019
The updated packages fix security vulnerabilities: ClamAV versions prior to 0.101.3 are susceptible to a zip bomb vulnerability where an unauthenticated attacker can cause a denial of service condition by sending crafted messages to an affected system. (CVE-2019-12625) BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors. (CVE-2019-12900)

Affected Products

VendorProductVersionsPlatforms
Mageiaclamav0 (affected), 0.101.4-1.1.mga7 (unaffected)
Mageiac-icap-modules-extra0 (affected), 0.5.3-1.mga7 (unaffected)
Mageiaecap-clamav0 (affected), 2.0.0-3.1.mga7 (unaffected)

Browse GCVE Records

74,267 records in the GCVE database · Updated July 22, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›