[Pkg-clamav-devel] Bug#675558: Off list :Re: Bug#675558: Is this also causing these other errors?

Karl Schmidt karl at xtronics.com
Sun May 4 19:31:12 UTC 2014


On 05/04/2014 09:35 AM, Andreas Cadhalpun wrote:
> Hi Karl,
>
> On 30.04.2014 04:27, Karl Schmidt wrote:
>>> LibClamAV info: scancws: Error decompressing SWF file
>>> LibClamAV info: scancws: Error decompressing SWF file
>>> LibClamAV info: scancws: Error decompressing SWF file
>>> LibClamAV info: scancws: Error decompressing SWF file
>>> LibClamAV Warning: cli_scanxz: decompress file size exceeds limits -
>>> only scanning 27262976 bytes
>>> LibClamAV info: scancws: Error decompressing SWF file
>>> LibClamAV Error: cli_scanswf: GETBITS: Can't read file
>>
>> One has to do something like:
>>
>> $ clamscan -r / > clamav.log 2>&1
>>
>> And then grep for the errors to find the directory involved - but all of
>> these errors have to do with decompression and I can't recreate the
>> errors using other tools - there appears to be no problems with the files.
>
> Can you provide an example SWF file that produces this errors?
> Can you disassemble these files with flasm?

I'm getting

# # clamscan -r . > clamav.log 2>&1
# cat clamav.log
./note_t2-v2conversion.pdf: OK
./V2K_S2E_S2T_Profibus_Module_User_Manual_2621.pdf: OK
LibClamAV info: scancws: Error decompressing SWF file
./V2k_bro_s2t_s2e_opt.pdf: OK
./V2k_windows_moduals.pdf: OK
<snip >

I was assuming that it is the PDF one line above that is the problem - but that seems to not be the 
case (all the files end up with a line listing them as "ok".) It seems it would be important for the 
error line to point to the file..

It was a process of elimination to determine which file caused the problem.

# flasm -x V2000flyer.pdf
Input file doesn't appear to be an SWF file..

I've attached the file.








>
>> If they are not using the normal libs for expanding compressed files, it
>> could explain these errors as well?
>
> Anyway I'm pretty sure this error has nothing to do with libmspack, because this is not used to
> decompress SWF files (instead clamav uses some code based on flasm for this).
>
> About the "embedded copy" of libmspack in clamav:
> It is a modified version of what libmspack had been back in 2004 and has very little correlation
> with the package libmspack currently in Debian, so it can't be simply replaced with that.
>
> Best regards,
> Andreas
>


-- 
--------------------------------------------------------------------------------
Karl Schmidt                                  EMail Karl at xtronics.com
Transtronics, Inc.                              WEB http://xtronics.com
3209 West 9th Street                             Ph (785) 841-3089
Lawrence, KS 66049                              FAX (785) 841-0434

History may not repeat itself, but it does rhyme a lot. -Mark Twain

--------------------------------------------------------------------------------
-------------- next part --------------
A non-text attachment was scrubbed...
Name: V2000flyer.pdf
Type: application/pdf
Size: 3066612 bytes
Desc: not available
URL: <http://lists.alioth.debian.org/pipermail/pkg-clamav-devel/attachments/20140504/81dbc023/attachment-0001.pdf>


More information about the Pkg-clamav-devel mailing list