From bd3fa397e7cea70766838e0dd14bc82c20b5d1ed Mon Sep 17 00:00:00 2001 From: micasnyd Date: Tue, 15 Aug 2023 01:25:00 +0000 Subject: [PATCH] News: Add notes for changes in 0.103.9 patch version --- NEWS.md | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/NEWS.md b/NEWS.md index 518f2da2d5..23b36f5384 100644 --- a/NEWS.md +++ b/NEWS.md @@ -7,7 +7,19 @@ Note: This file refers to the source tarball. Things described here may differ ClamAV 0.103.9 is a critical patch release with the following fixes: +- [CVE-2023-20197](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-20197) + Fixed a possible denial of service vulnerability in the HFS+ file parser. + This issue affects versions 1.1.0, 1.0.1 through 1.0.0, 0.105.2 through 0.105.0, + 0.104.4 through 0.104.0, and 0.103.8 through 0.103.0. + Thank you to Steve Smith for reporting this issue. + +- Fixed compiler warnings that may turn into errors in Clang 16. + Patch courtesy of Michael Orlitzky. + - GitHub pull request: https://github.com/Cisco-Talos/clamav/pull/747 + Special thanks to the following people for code contributions and bug reports: +- Michael Orlitzky +- Steve Smith ## 0.103.8