Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Fri, 9 Apr 2010 11:50:50 +0200
From: Ludwig Nussel <ludwig.nussel@...e.de>
To: oss-security@...ts.openwall.com
Subject: Re: ClamAV small issues

Eren Türkay wrote:
> On Friday 09 April 2010 11:30:19 am Ludwig Nussel wrote:
> > Do such issues really need to be flagged as vulnerabilities? A virus
> > scanner cannot detect all possible malware in any possible container
> > anyways. So it's kind of natural that new releases enhance the
> > methods to find even more hiding places.
> > 
> 
> I guess many people who deploy e-mail service with linux use ClamAV to scan 
> the attachments. Accordingly to ClamAV bug #1771 (CVE-2010-1311), it is 
> possible to crash the daemon with crafted file, which is not the intended 
> behavior.

Sure. That's a different issue though. I was referring to CVE-2010-0098.

cu
Ludwig

-- 
 (o_   Ludwig Nussel
 //\   
 V_/_  http://www.suse.de/
SUSE LINUX Products GmbH, GF: Markus Rex, HRB 16746 (AG Nuernberg)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.