Bug 60865

Summary: Critical Update for security/clamav-devel
Product: Ports & Packages Reporter: rob
Component: Individual Port(s)Assignee: freebsd-ports-bugs (Nobody) <ports-bugs>
Status: Closed FIXED    
Severity: Affects Only Me    
Priority: Normal    
Version: Latest   
Hardware: Any   
OS: Any   
Attachments:
Description Flags
clamav-devel.patch none

Description rob 2004-01-03 17:00:33 UTC
Critical Update for security/clamav-devel
Mote that the distfiles 'hack' is very temporary, and will be removed 
in the next update.

(E-mail from the dev-list):
----------------------------------------------------------------------
Dear Users,

all ClamAV snapshots newer than clamav-20031201 contain a bug that
completely disables detection of polymorphic viruses (Hybris, Magistr)
and other malware with multipart signatures. Please update to the latest
version and make sure the changelog contains the following entry:

* libclamav: fixed handling of multipart signatures (broken since
	     Dec 2). The bug was introduced by _me_ and not by the
             Thomas Lamy's patch. Problem found and reported by René
             Bellora <rbellora*tecnoaccion.com.ar>, Jean-Christophe
             Heger <jcheger*acytec.com> and Tomasz Papszun
             <tomek*clamav.net>.  Many thanks !

ClamAV 0.65 is NOT affected by this problem.

Best regards,
Tomasz Kojm
------------------------------------------------------------------------
Comment 1 Pete Fritchman freebsd_committer freebsd_triage 2004-01-05 03:56:27 UTC
State Changed
From-To: open->closed

Committed, thanks.  I kept using DISTNAME (no reason to switch to 
DISTFILES unless multiple files are involved), and added the WRKSRC 
line after the DEPENDS section.