Forums

Resolved
2 votes
CVE-2023-40477 affects the unrar library packaged with ClamAV. Various sources score the vulnerability differently from High to Critical. ClamAV have released an update to mitigate this vulnerability - announcement.

This is the 3rd or fourth critical vulnerability in the ClamAV package that ClearOS is now exposed to. It affects the File Scanner, Mail Antivirus and Gateway Antivirus apps. As always, I have updated the ClearOS package ready for them to incorporate into their build system and distribute through their repos. I really hope, for everyone's sake, that they do update the package.
Saturday, September 09 2023, 08:07 AM
Share this post:
Responses (6)
  • Accepted Answer

    Mick L
    Mick L
    Offline
    Sunday, October 01 2023, 09:21 AM - #Permalink
    Resolved
    0 votes
    Oh, OK. Thanks for the heads up.
    The reply is currently minimized Show
  • Accepted Answer

    Saturday, September 30 2023, 04:17 PM - #Permalink
    Resolved
    0 votes
    Mick L wrote:

    Newbe trying out ClearOS here. Has there been an update to this?

    No. And i don’t expect any
    Centos 7 is almost EOL and COS is a bit abanded.
    A lot of users had moved to another distro
    The reply is currently minimized Show
  • Accepted Answer

    Mick L
    Mick L
    Offline
    Saturday, September 30 2023, 09:30 AM - #Permalink
    Resolved
    1 votes
    Newbe trying out ClearOS here. Has there been an update to this?
    The reply is currently minimized Show
  • Accepted Answer

    Thursday, September 14 2023, 08:58 AM - #Permalink
    Resolved
    0 votes
    Hi Nick,

    Is it possible to upload the rpm to another location so everyone can install it?

    Cheers!
    The reply is currently minimized Show
  • Accepted Answer

    Wednesday, September 13 2023, 05:02 PM - #Permalink
    Resolved
    0 votes
    Thanks Nick! Nothing yet that I can see in updates/repos.

    John

    PS If you guys really want updates, you really do need to make contact with Nick.
    The reply is currently minimized Show
  • Accepted Answer

    Saturday, September 09 2023, 04:23 PM - #Permalink
    Resolved
    0 votes
    Great job Nick
    I looks like you are the only one who is active and you even not a officially ClearOS member any more
    Hopely they will come with updates very soon to secure the unsafe vulnerabilities
    The reply is currently minimized Show
Your Reply