Re: [Security-Discuss] Firefox Backport Request to 10.1

Michael Scherer <[email protected]>
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
Le Mardi 17 Mai 2005 11:26, dieter-ZpcFK/w3DkEX+nLd/[email protected] a écrit :
> > The last clamav update we put out was in January, and that was based
> > on the maintainer's request (it was 0.81).  I wasn't aware there is a
> > security hole in clamav prior to 0.85.  Is there?  Do you have a CVE
> > name handy, because I sure don't.  You're just looking for the
> > "latest and greatest", no?
>
> Aaah thank you, you open my eyes.
> You don't think there is a security risc about crahing clamav sometimes.

Is  the crash reproductible ? 
At work, we use clamav 0.83, and we didn't see any  clamav crash since 6 
months.

How does it impact your security system ?

If this is a real security risk, then, there should be something, like CVE 
name.

I hope you stop processing if clamav is stopped, because doing otherwise would 
be the real problem ( unless you are pretty confident that nothing can crash 
clamav ). You can also configure nagios with snmp to send you a email if 
clamav crashed. 


> You don't think there is a security risc if clamav let viruses path
> through. These are fixes in the 0.84 Version.

The security problem is not on linux side. 
So, if you really want to fix it, just  secure your workstation ( ie not use 
insecure email client, or even insecure os ) or filter directly all 
attachements.

Or learn to your user to not open bad attachement.

I do not see why this should be the work of a linux distribution to fix 
security problem in another closed source crappy os like windows.

> But thank you for the introdution on security

It was not a introduction to security, he was explaining  why clamav was not 
updated. 
So far, you didn't answer to any question he asked, maybe it would be more 
useful instead of being sarcastic ?


-- 
Michael Scherer
message.footer (text/plain, 239 B)
____________________________________________________
Want to buy your Pack or Services from MandrakeSoft? 
Go to http://www.mandrakestore.com
Join the Club : http://www.mandrakeclub.com
____________________________________________________
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.