Hi, I couldn't find any other relevant information on that, hence my question.
I would like to have the clamav package in pkgsrc fixed (and I'm sure I
share that wish with all software packagers). I saw that something that
really looks like a fix went into CVS ("Make sure the property tree
doesn't loop" in libclamav/ole2_extract.c), and it indeed fixes the
issue with the Word document posted on the Debian bug page
(http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=333566).
So, is that fix the real thing? Are there other issues to consider, or
can it go into our package so that we don't have a vulnerable ClamAV
anymore?
--
Quentin Garnier - [EMAIL PROTECTED] - [EMAIL PROTECTED]
"When I find the controls, I'll go where I like, I'll know where I want
to be, but maybe for now I'll stay right here on a silent sea."
KT Tunstall, Silent Sea, Eye to the Telescope, 2004.
pgpOl5l3qGsZl.pgp
Description: PGP signature
_______________________________________________ http://lurker.clamav.net/list/clamav-users.html
