[Clamav-announce] Critical bug in virus scanning engine (development versions only) (fwd)

Raymond Dijkxhoorn raymond at PROLOCATION.NET
Sat Jan 3 11:20:26 GMT 2004


---------- Forwarded message ----------
Date: Sat, 3 Jan 2004 11:33:47 +0100
From: Tomasz Kojm <tk at lodz.tpnet.pl>
To: clamav-announce at lists.sourceforge.net
Cc: clamav-users at lists.sourceforge.net, clamav-devel at lists.sourceforge.net
Subject: [Clamav-announce] Critical bug in virus scanning engine
    (development versions only)

Dear Users,

all ClamAV snapshots newer than clamav-20031201 contain a bug that
completely disables detection of polymorphic viruses (Hybris, Magistr)
and other malware with multipart signatures. Please update to the latest
version and make sure the changelog contains the following entry:

* libclamav: fixed handling of multipart signatures (broken since
             Dec 2). The bug was introduced by _me_ and not by the
             Thomas Lamy's patch. Problem found and reported by René
             Bellora <rbellora*tecnoaccion.com.ar>, Jean-Christophe
             Heger <jcheger*acytec.com> and Tomasz Papszun
             <tomek*clamav.net>.  Many thanks !

ClamAV 0.65 is NOT affected by this problem.

Best regards,
Tomasz Kojm
      oo    .....       tkojm at clamav.net          www.ClamAV.net
     (\/)\.........     http://www.clamav.net/gpg/tkojm.gpg
        \..........._   0DCA5A08407D5288279DB43454822DC8985A444B
          //\   /\      Sat Jan  3 11:27:24 CET 2004

More information about the MailScanner mailing list