[CLA-2005:928] Conectiva Security Announcement - clamav
Date: Thu, 3 Mar 2005 15:38:05 -0300
To: [email protected], [email protected],
Subject: [CLA-2005:928] Conectiva Security Announcement - clamav
From: Conectiva Updates <secure@conectiva.com.br.>
X-Mailer: SAC - Sistema de Anuncios Conectiva v1.2 (PHP/3.0.18)
X-Virus-Scanned: by amavisd-new at conectiva.com.br
X-Virus-Scanned: antivirus-gw at tyumen.ru
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
- --------------------------------------------------------------------------
CONECTIVA LINUX SECURITY ANNOUNCEMENT
- --------------------------------------------------------------------------
PACKAGE : clamav
SUMMARY : Fix for denial of service in clamav
DATE : 2005-03-03 14:40:00
ID : CLA-2005:928
RELEVANT
RELEASES : 10
- -------------------------------------------------------------------------
DESCRIPTION
Clamav[1] is an anti-virus utility for Unix/Linux.
This announcement updates clamav so it is able to update its database
from the server without any problems related to its format and also
because it fixes a security issue which could lead to a denial of
service[2] situation.
SOLUTION
It is recommended that all clamav users upgrade their packages. This
update will automatically restart the service if it is already
running.
REFERENCES
1.http://www.clamav.net/
2.http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0133
UPDATED PACKAGES
ftp://atualizacoes.conectiva.com.br/10/SRPMS/clamav-0.83-70136U10_7cl.src.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/clamav-0.83-70136U10_7cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/clamav-database-0.83.20041125-70136U10_7cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/libclamav-devel-0.83-70136U10_7cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/libclamav-devel-static-0.83-70136U10_7cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/libclamav1-0.83-70136U10_7cl.i386.rpm
ADDITIONAL INSTRUCTIONS
The apt tool can be used to perform RPM packages upgrades:
- run: apt-get update
- after that, execute: apt-get upgrade
Detailed instructions regarding the use of apt and upgrade examples
can be found at http://distro.conectiva.com.br/atualizacoes/#apt?idioma=en
- -------------------------------------------------------------------------
All packages are signed with Conectiva's GPG key. The key and instructions
on how to import it can be found at
http://distro.conectiva.com.br/seguranca/chave/?idioma=en
Instructions on how to check the signatures of the RPM packages can be
found at http://distro.conectiva.com.br/seguranca/politica/?idioma=en
- -------------------------------------------------------------------------
All our advisories and generic update instructions can be viewed at
http://distro.conectiva.com.br/atualizacoes/?idioma=en
- -------------------------------------------------------------------------
Copyright (c) 2004 Conectiva Inc.
http://www.conectiva.com
- -------------------------------------------------------------------------
subscribe: [email protected]
unsubscribe: [email protected]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org
iD8DBQFCJ1mM42jd0JmAcZARAkJPAJ9sMqPbrC9t0oW4sh4BhQ/1GLAZGACeJ3lI
2V+/t0wwHgw08Ds+69YpXfQ=
=03tu
-----END PGP SIGNATURE-----