Bug 106620 - security/clamav: Update clamav to .88.7 (dos attack)
Summary: security/clamav: Update clamav to .88.7 (dos attack)
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Only Me
Assignee: Renato Botelho
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2006-12-11 22:30 UTC by Michael Scheidell
Modified: 2006-12-12 17:10 UTC (History)
1 user (show)

See Also:


Attachments
file.diff (539 bytes, patch)
2006-12-11 22:30 UTC, Michael Scheidell
no flags Details | Diff
file.diff (257 bytes, patch)
2006-12-11 22:30 UTC, Michael Scheidell
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Michael Scheidell 2006-12-11 22:30:12 UTC
.88.6 clamav may have an untar recoursion DOS attack problem.

Fix: update to .88.7, patch included.
How-To-Repeat: specially crafter tar archive can cause a DOS using clamav .88.6.
Comment 1 Shaun Amott freebsd_committer freebsd_triage 2006-12-11 22:43:04 UTC
Responsible Changed
From-To: freebsd-ports-bugs->garga

Over to maintainer.
Comment 2 Marcus Alves Grando freebsd_committer freebsd_triage 2006-12-12 17:03:32 UTC
State Changed
From-To: open->closed

Committed. Thanks!
Comment 3 dfilter service freebsd_committer freebsd_triage 2006-12-12 17:08:21 UTC
mnag        2006-12-12 17:03:25 UTC

  FreeBSD ports repository

  Modified files:
    security/clamav      Makefile distinfo 
  Log:
  - Update clamav to 0.88.7
  
  PR:             106620
  Submitted by:   Michael Scheidell <scheidell___secnap.net>
  Approved by:    maintainer timeout (18 hours)
  With hat:       secteam
  Security:       http://secunia.com/advisories/23347/, http://www.quantenblog.net/security/virus-scanner-bypass
  
  Revision  Changes    Path
  1.85      +1 -1      ports/security/clamav/Makefile
  1.35      +3 -3      ports/security/clamav/distinfo
_______________________________________________
cvs-all@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/cvs-all
To unsubscribe, send any mail to "cvs-all-unsubscribe@freebsd.org"