First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 174375
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 174375 depends on: Show dependency tree
Show dependency graph
Bug 174375 blocks:

Additional Comments: (this is where you put emerge --info)







View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-04-13 07:17 0000
Not sure how serius this is.

From 0.90.2 Changelog

    - libclamav/chmunpack.c: fix fd leak in chm_decompress_stream
      (CVE-2007-1745)
    - libclamav/cab.c: fix buffer overflow, reported through iDefense
      Vulnerability Contributor Program (CVE-2007-1997)
    - libclamav/pdf.c: Fix fd leak on empty objects. Scan in user memory
    - libclamav/lockdb.c: fix fd leak on EACCES/EAGAIN (bb#400)

------- Comment #1 From Andrej Kacian (RETIRED) 2007-04-13 08:47:50 0000 -------
Ebuild is in the tree. The nls patch update mentioned in the changelog
shouldn't stop anyone from security-stabilizing this version - if anything, it
will produce less bugs than the previous patch. :)

------- Comment #2 From Sune Kloppenborg Jeppesen 2007-04-13 10:07:56 0000 -------
Thx Ticho.

Arches please test and mark stable. Target keywords are:

clamav-0.90.2.ebuild:KEYWORDS="alpha amd64 hppa ia64 ppc ppc64 sparc x86
~x86-fbsd"

------- Comment #3 From Raúl Porcel 2007-04-13 11:34:08 0000 -------
ia64 + x86 stable

------- Comment #4 From Gustavo Zacarias (RETIRED) 2007-04-13 14:03:21 0000 -------
sparc stable.

------- Comment #5 From Fernando J. Pereda 2007-04-13 14:47:37 0000 -------
Alpha done.

------- Comment #6 From Peter Weller 2007-04-13 14:56:11 0000 -------
amd64 done

------- Comment #7 From Tobias Scherbaum 2007-04-13 16:31:47 0000 -------
ppc stable

------- Comment #8 From Jeroen Roovers 2007-04-13 19:25:44 0000 -------
Stable for HPPA.

------- Comment #9 From Jeremy Huddleston 2007-04-13 20:26:31 0000 -------
You should get the patch in bug #174512 in asap as well so users don't have
trouble restarting their clamd process when they do this security update.

------- Comment #10 From Andrej Kacian (RETIRED) 2007-04-13 20:57:42 0000 -------
(In reply to comment #9)
> You should get the patch in bug #174512 in asap as well so users don't have
> trouble restarting their clamd process when they do this security update.
> 

It is in. Thanks and sorry for the omission.

------- Comment #11 From Markus Rothe 2007-04-15 19:21:15 0000 -------
ppc64 stable

------- Comment #12 From Sune Kloppenborg Jeppesen 2007-04-17 05:29:55 0000 -------
Since this is rated B2/3 I'm calling a vote. I vote YES.

------- Comment #13 From Pierre-Yves Rofes 2007-04-19 10:35:42 0000 -------
voting YES.

------- Comment #14 From NETwork.ORGanization - Alexander Schoberl 2007-04-20 00:46:03 0000 -------
After updating to 0.90-2 the clamscan will need a lot of time for scanning.

# /usr/bin/clamscan - </dev/null
stdin: OK
----------- SCAN SUMMARY -----------
Known viruses: 215418
Engine version: 0.90.2
Scanned directories: 0
Scanned files: 1
Infected files: 0
Data scanned: 0.00 MB
Time: 53.279 sec (0 m 53 s)

Any resolving idea about this ??

------- Comment #15 From Andrej Kacian (RETIRED) 2007-04-22 05:38:06 0000 -------
(In reply to comment #14)
> After updating to 0.90-2 the clamscan will need a lot of time for scanning.

That's an upstream issue, and is/was discussed on upstream mailing lists, if i
remember correctly. It's unrelated to this bugzilla entry.

------- Comment #16 From Matthias Geerdsen 2007-04-23 15:21:22 0000 -------
updating status, GLSA is in the queue

------- Comment #17 From Matthias Geerdsen 2007-04-24 15:52:19 0000 -------
GLSA 200704-21

thanks everyone

First Last Prev Next    No search results available      Search page      Enter new bug