Re: [Security-Discuss] Firefox Backport Request to 10.1
Vincent Danen <vdanen-4qZELD6FgxhWk0Htik3J/[email protected]>
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
On 17-May-05, at 3:26 AM, dieter-ZpcFK/w3DkEX+nLd/[email protected] wrote: >> The last clamav update we put out was in January, and that was based >> on the maintainer's request (it was 0.81). I wasn't aware there is a >> security hole in clamav prior to 0.85. Is there? Do you have a CVE >> name handy, because I sure don't. You're just looking for the >> "latest and greatest", no? >> > > Aaah thank you, you open my eyes. I doubt it. You still don't seem to be quite to sure what you're talking about. > You don't think there is a security risc about crahing clamav > sometimes. Sometimes? Or always? Come on. Everything crashes "sometimes". Heck, my dad has a problem where when he copies files to his home folder on CS2.1 using samba that smbd dies and causes a kernel panic. Am I rushing out to make an update for his problem? No. Because a) it's not consistently reproducable, b) it never did it before, and c) I think his bloody drive is failing. As a result, I don't consider his crashing smbd "sometimes" (which is far more extreme than your clamav crashing "sometimes" to be a security problem. > You don't think there is a security risc if clamav let viruses path > through. Of course not. Is clamav 100% effective? If it's not, you shouldn't be using it because those 2% of viruses it may let through make it unreliable and a security risk. Don't be silly. clamav letting viruses through is not a security risk to the system.. it might be a pain for Windows users but they should be using their own anti-virus software anyways. Hey, maybe you do need some lessons on security. Here's a quick trainer (my bill is in the mail): Don't rely on the server to do your virus scanning for you. Every client machine should have their own virus scanner. Do you think clamav is going to magically scan their systems when they download some ugly screen saver that is cute for the day? I think not. Each client should have their own virus scanner (sure it may cost you a lot if you go the commercial route, but there is clamav for Windows as well... unfortunately, you can't be lazy with that one since Microsoft won't update clamav for you... you actually get to do some work! yippee!) Also, if your mail system was setup properly, you'd be deferring mails if clamav wasn't scanning them (ie. if clamav is down, defer the mails for later processing until clamav is up). Would you like me to set that up for you as well? In short, no, I don't think there is a security risk if you insist on using a) an insecure OS and b) don't know how to configure your mail server. Seriously, if you want to play with the big boys, you have to learn how to use the toys properly. > These are fixes in the 0.84 Version. I'm glad to hear that 0.84 fixes bugs. I'm sure 0.85 and 0.85.1 do as well. But since none of these bugs are security-related (they're "I use a crappy OS for a workstation" and "I don't know how to configure a mail server properly" -related), they really don't concern me. > But thank you for the introdution on security I could teach you a lot more if you weren't so obstinate. But then I'd also have to charge you for it since I don't teach... people like you... for free. I've had enough with this thread. I've also decided (and thank you for opening my eyes) that an update to clamav isn't required because none of this is security related. Thank you for opening *my* eyes and letting me know that the problem is you don't know what you're doing and isn't directly related to clamav. Thank you. -- "lynx -source http://linsec.ca/vdanen.asc | gpg --import" {FEE30AD4 : 7F6C A60C 06C2 4811 FA1C A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig
(application/pgp-signature, 186 B) - not displayed