Security fixes from clamav 0.95 need backport
Bug #354190 reported by
Scott Kitterman
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Dapper Backports |
Fix Released
|
Undecided
|
Unassigned | ||
Hardy Backports |
Fix Released
|
High
|
Scott Kitterman | ||
clamav (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
Dapper |
Fix Released
|
Undecided
|
Unassigned | ||
Gutsy |
Won't Fix
|
Undecided
|
Unassigned | ||
Hardy |
Fix Released
|
Undecided
|
Unassigned | ||
Intrepid |
Fix Released
|
Medium
|
Scott Kitterman |
Bug Description
Binary package hint: clamav
Clamav 0.95 included patches for two security issues:
*libclamav/pe.c: division by zero with --detect-broken (bb#1335) (Denial of
service)
* libclamav/untar.c: infloop in tar.c (bb#1462) (Denial of Service)
Fixed in Jaunty by 0.95. Open for other Ubuntu releases.
visibility: | private → public |
Changed in clamav (Ubuntu): | |
status: | New → Fix Released |
Changed in clamav (Ubuntu Intrepid): | |
assignee: | nobody → kitterman |
importance: | Undecided → Medium |
status: | New → In Progress |
Changed in hardy-backports: | |
assignee: | nobody → kitterman |
importance: | Undecided → High |
status: | New → In Progress |
Changed in hardy-backports: | |
status: | In Progress → Fix Released |
Changed in dapper-backports: | |
status: | New → Fix Released |
Changed in clamav (Ubuntu Dapper): | |
status: | New → Triaged |
Changed in clamav (Ubuntu Hardy): | |
status: | New → In Progress |
Changed in clamav (Ubuntu Dapper): | |
status: | Triaged → Fix Committed |
Changed in clamav (Ubuntu Hardy): | |
status: | In Progress → Fix Committed |
To post a comment you must log in.
Intrepid debdiff attached. My recommended approach for the other releases is:
After intrepid is updated, backport intrepid-security to dapper-backports and hardy-backports and then push 0.94.2 with rdepends to dapper-security and hardy-security. Let Gutsy rest in peace with 0.92.2. That will get us down to two supported versions and we can start working on clamav 0.95 backports.