[Pkg-clamav-devel] Bug#684697: Bug#684697: Upgrade severity

Daniel Tryba daniel at pocos.nl
Tue Aug 14 15:33:33 UTC 2012


On Tuesday 14 August 2012 17:04:21 Scott Kitterman wrote:
> > This is not a normal bug, there is a huge potential lost of lots of
> > legitimate mail due to this bug. In my case a backup MX without this
> > update saved my ass.
> 
> OK.  Can you specify the conditions under which the problem occurs so we
> can replicate it, verify both the severity of the issue and the fix?  If
> so, I'll look into cherrypicking the patch and getting it into Debian in
> advance of the next clamav release.

No specifics, queue has been flushed. I saw some legit emails with Excel 
attachments being blocked, just like this second comment suggests:
https://bugzilla.clamav.net/show_bug.cgi?id=5252#c2

And just like in 13th comment:
http://ftp.mozilla.org/pub/mozilla.org/thunderbird/nightly/14.0b4-
candidates/build1/linux-i686/en-GB/thunderbird-14.0b4.tar.bz2
will trigger the error in the new package:

0.97.3+dfsg-1~squeeze1:
$ clamscan /tmp/thunderbird-14.0b4.tar.bz2 
/tmp/thunderbird-14.0b4.tar.bz2: OK

0.97.5+dfsg-3~squeeze1:
$ clamscan /tmp/thunderbird-14.0b4.tar.bz2 
/tmp/thunderbird-14.0b4.tar.bz2: CL_EFORMAT: Bad format or broken data ERROR


-- 

POCOS B.V. - Croy 9c - 5653 LC Eindhoven
Telefoon: 040 293 8661 - Fax: 040 293 8658
http://www.pocos.nl/   - http://www.sipo.nl/
K.v.K. Eindhoven 17097024



More information about the Pkg-clamav-devel mailing list