Overview

Request 623520 superseded

clamav 0.100.1

CVE-2018-0360: HWP integer overflow, infinite loop
vulnerability (bsc#1101410)
CVE-2018-0361: PDF object length check, unreasonably long time
to parse relatively small file (bsc#1101412)

Loading...
Request History
Andreas Stieger's avatar

AndreasStieger created request

clamav 0.100.1

CVE-2018-0360: HWP integer overflow, infinite loop
vulnerability (bsc#1101410)
CVE-2018-0361: PDF object length check, unreasonably long time
to parse relatively small file (bsc#1101412)


Factory Auto's avatar

factory-auto added opensuse-review-team as a reviewer

Please review sources


Factory Auto's avatar

factory-auto added repo-checker as a reviewer

Please review build success


Factory Auto's avatar

factory-auto accepted review

Check script succeeded


Staging Bot's avatar

staging-bot added as a reviewer

Being evaluated by staging project "openSUSE:Factory:Staging:adi:86"


Staging Bot's avatar

staging-bot accepted review

Picked openSUSE:Factory:Staging:adi:86


Repo Checker's avatar

repo-checker accepted review

cycle and install check passed


Saul Goodman's avatar

licensedigger declined review

@babelworx declined the legal report with the following comment: Explain how yara is used. It is Apache-2.0 and not GPL-2.0 compatible:

clamav-0.100.1/COPYING.YARA
clamav-0.100.1/libclamav/pe.c
clamav-0.100.1/libclamav/yara_arena.c
clamav-0.100.1/libclamav/yara_arena.h
clamav-0.100.1/libclamav/yara_clam.h
clamav-0.100.1/libclamav/yara_compiler.c
clamav-0.100.1/libclamav/yara_compiler.h
clamav-0.100.1/libclamav/yara_exec.c
clamav-0.100.1/libclamav/yara_exec.h
clamav-0.100.1/libclamav/yara_grammar.y
clamav-0.100.1/libclamav/yara_hash.c
clamav-0.100.1/libclamav/yara_hash.h
clamav-0.100.1/libclamav/yara_lexer.c
clamav-0.100.1/libclamav/yara_lexer.h
clamav-0.100.1/libclamav/yara_lexer.l
clamav-0.100.1/libclamav/yara_parser.c
clamav-0.100.1/libclamav/yara_parser.h


Saul Goodman's avatar

licensedigger declined request

@babelworx declined the legal report with the following comment: Explain how yara is used. It is Apache-2.0 and not GPL-2.0 compatible:

clamav-0.100.1/COPYING.YARA
clamav-0.100.1/libclamav/pe.c
clamav-0.100.1/libclamav/yara_arena.c
clamav-0.100.1/libclamav/yara_arena.h
clamav-0.100.1/libclamav/yara_clam.h
clamav-0.100.1/libclamav/yara_compiler.c
clamav-0.100.1/libclamav/yara_compiler.h
clamav-0.100.1/libclamav/yara_exec.c
clamav-0.100.1/libclamav/yara_exec.h
clamav-0.100.1/libclamav/yara_grammar.y
clamav-0.100.1/libclamav/yara_hash.c
clamav-0.100.1/libclamav/yara_hash.h
clamav-0.100.1/libclamav/yara_lexer.c
clamav-0.100.1/libclamav/yara_lexer.h
clamav-0.100.1/libclamav/yara_lexer.l
clamav-0.100.1/libclamav/yara_parser.c
clamav-0.100.1/libclamav/yara_parser.h


Reinhard Max's avatar

rmax superseded request

superseded by 626469

openSUSE Build Service is sponsored by