clamav-daemon (clamd) abends
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
ClamAV |
Confirmed
|
High
|
|||
clamav (Ubuntu) |
Confirmed
|
Undecided
|
Unassigned |
Bug Description
On Ubuntu 16.04.6 LTS
clamd will abend with nothing logged meaning mail will fail with a 451 error at the end of the DATA section.
Package clamav-daemon 0.100.2+
Enabling debug mode on clamd gives one the following:
Mar 01 11:38:39 mail clamd[7520]: clamd: yara_exec.c:177: yr_execute_code: Assertion `sp == 0' failed.
Mar 01 11:38:39 mail systemd[1]: clamav-
Mar 01 11:38:39 mail clamsmtpd[492]: 10007F: clamd disconnected unexpectedly
Mar 01 11:38:39 mail systemd[1]: clamav-
Mar 01 11:38:39 mail clamsmtpd[492]: 10007F: from=******, to=******
Mar 01 11:38:39 mail systemd[1]: clamav-
Appears related to https:/
and the workaround suggested in that thread restores service.
Changed in clamav: | |
importance: | Unknown → High |
status: | Unknown → Confirmed |
Created attachment 7406
backtrace with debuginfo
I'm use clamav- unofficial- sigs.sh for additional clamav databases. antivm. yar
I found clamav-0.100.0-rc crashes with packer.yar and antidebug_
I will attach backtrace, clamd output, db examples.
Sat Apr 7 13:13:41 2018 -> Database correctly reloaded (13394577 signatures)
[New Thread 0x7fffbcb12700 (LWP 30615)]
clamd: yara_exec.c:177: yr_execute_code: Assertion `sp == 0' failed.