Re: [Security-Discuss] Firefox Backport Request to 10.1

Vincent Danen <vdanen-4qZELD6FgxhWk0Htik3J/[email protected]>
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
On 17-May-05, at 3:26 AM, dieter-ZpcFK/w3DkEX+nLd/[email protected] wrote:

>> The last clamav update we put out was in January, and that was based
>> on the maintainer's request (it was 0.81).  I wasn't aware there is a
>> security hole in clamav prior to 0.85.  Is there?  Do you have a CVE
>> name handy, because I sure don't.  You're just looking for the
>> "latest and greatest", no?
>>
>
> Aaah thank you, you open my eyes.

I doubt it.  You still don't seem to be quite to sure what you're  
talking about.

> You don't think there is a security risc about crahing clamav  
> sometimes.

Sometimes?  Or always?  Come on.  Everything crashes "sometimes".   
Heck, my dad has a problem where when he copies files to his home  
folder on CS2.1 using samba that smbd dies and causes a kernel  
panic.  Am I rushing out to make an update for his problem?  No.   
Because a) it's not consistently reproducable, b) it never did it  
before, and c) I think his bloody drive is failing.  As a result, I  
don't consider his crashing smbd "sometimes" (which is far more  
extreme than your clamav crashing "sometimes" to be a security problem.

> You don't think there is a security risc if clamav let viruses path  
> through.

Of course not.  Is clamav 100% effective?  If it's not, you shouldn't  
be using it because those 2% of viruses it may let through make it  
unreliable and a security risk.  Don't be silly.  clamav letting  
viruses through is not a security risk to the system.. it might be a  
pain for Windows users but they should be using their own anti-virus  
software anyways.  Hey, maybe you do need some lessons on security.   
Here's a quick trainer (my bill is in the mail):

Don't rely on the server to do your virus scanning for you.  Every  
client machine should have their own virus scanner.  Do you think  
clamav is going to magically scan their systems when they download  
some ugly screen saver that is cute for the day?  I think not.  Each  
client should have their own virus scanner (sure it may cost you a  
lot if you go the commercial route, but there is clamav for Windows  
as well... unfortunately, you can't be lazy with that one since  
Microsoft won't update clamav for you... you actually get to do some  
work!  yippee!)

Also, if your mail system was setup properly, you'd be deferring  
mails if clamav wasn't scanning them (ie. if clamav is down, defer  
the mails for later processing until clamav is up).  Would you like  
me to set that up for you as well?

In short, no, I don't think there is a security risk if you insist on  
using a) an insecure OS and b) don't know how to configure your mail  
server.  Seriously, if you want to play with the big boys, you have  
to learn how to use the toys properly.

> These are fixes in the 0.84 Version.

I'm glad to hear that 0.84 fixes bugs.  I'm sure 0.85 and 0.85.1 do  
as well.  But since none of these bugs are security-related (they're  
"I use a crappy OS for a workstation" and "I don't know how to  
configure a mail server properly" -related), they really don't  
concern me.

> But thank you for the introdution on security

I could teach you a lot more if you weren't so obstinate.  But then  
I'd also have to charge you for it since I don't teach... people like  
you... for free.

I've had enough with this thread.

I've also decided (and thank you for opening my eyes) that an update  
to clamav isn't required because none of this is security related.   
Thank you for opening *my* eyes and letting me know that the problem  
is you don't know what you're doing and isn't directly related to  
clamav.

Thank you.

-- 
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C  A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig (application/pgp-signature, 186 B) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.