New ClamAV security patch closes seven scanner bugs dating back two decades

The ClamAV open-source antivirus engine has released patches for seven security vulnerabilities, some of which have existed in the codebase for two decades. The fixes address issues in file parsing and unpacking that could lead to system crashes or buffer overflows.
Why it matters
ClamAV is a critical component in enterprise security gateways; patching these long-standing bugs is essential to prevent potential remote code execution or denial-of-service attacks.
New ClamAV security patch closes seven scanner bugs dating back two decades Open source antivirus scanning sits inside mail gateways, file upload checks, and endpoint tooling at organizations of every size. Much of that work runs through ClamAV, the scanning engine maintained by Cisco’s Talos group. The project released two patch versions, 1.5.3 and 1.4.5, carrying fixes for seven security flaws along with smaller hardening changes.
The report is a technical summary of security patches and CVE disclosures without political or social framing.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in