Your message dated Wed, 13 Aug 2014 03:19:20 +0000
with message-id <[email protected]>
and subject line Bug#675558: fixed in clamav 0.98.5~beta1+dfsg-1
has caused the Debian Bug report #675558,
regarding Embedded code copies of libmspack
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
675558: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=675558
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: cabextract,evolution-ews,msn-pecan,clamav,calibre
Severity: normal
Tags: security
Hi,
the following packages include embedded copies of libmspack:
- cabextract can use the external libmspack, but it is not packaged in
Debian.
- evolution-ews includes a modified version of an older libmspack.
- msn-pecan includes a complete copy of an older libmspack, it could
probably be made to use it instead.
- clamav embeds a modified version of an older libmspack.
- calibre embeds a complete copy of an older libmspack, it could
probably be made to use an external one instead.
There may be other packages impacted. For example I found traces of it
in older versions of spamassassin and OOo. I have not conducted a
thorough check of the archive.
This report is here to track the issue and inform the security team of
its existence. If we want it fixed, someone needs to step up and package
libmspack so that other packages can use it instead of embedding.
Cheers,
--
.''`. Josselin Mouette
: :' :
`. `'
`-
--- End Message ---
--- Begin Message ---
Source: clamav
Source-Version: 0.98.5~beta1+dfsg-1
We believe that the bug you reported is fixed in the latest version of
clamav, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Scott Kitterman <[email protected]> (supplier of updated clamav package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Tue, 12 Aug 2014 22:50:34 -0400
Source: clamav
Binary: clamav-base clamav-docs clamav-dbg clamav libclamav-dev libclamav6
clamav-daemon clamav-testfiles clamav-freshclam clamav-milter
Architecture: source all i386
Version: 0.98.5~beta1+dfsg-1
Distribution: experimental
Urgency: medium
Maintainer: ClamAV Team <[email protected]>
Changed-By: Scott Kitterman <[email protected]>
Description:
clamav - anti-virus utility for Unix - command-line interface
clamav-base - anti-virus utility for Unix - base package
clamav-daemon - anti-virus utility for Unix - scanner daemon
clamav-dbg - debug symbols for ClamAV
clamav-docs - anti-virus utility for Unix - documentation
clamav-freshclam - anti-virus utility for Unix - virus database update utility
clamav-milter - anti-virus utility for Unix - sendmail integration
clamav-testfiles - anti-virus utility for Unix - test files
libclamav-dev - anti-virus utility for Unix - development files
libclamav6 - anti-virus utility for Unix - library
Closes: 675558 753973
Changes:
clamav (0.98.5~beta1+dfsg-1) experimental; urgency=medium
.
[ Joe Dalton ]
* Updated Danish Debconf template translation (Closes: #753973)
.
[ Andreas Cadhalpun ]
* Convert debian/copyright to DEP-5 copyright format 1.0.
* Add systemd socket activation to clamd and install systemd unit files
for clamav-daemon and clamav-freshclam.
* Ignore test failures on hurd, because sockets don't work in the build
chroot on the buildd.
* Fix implicit declaration warnings.
* Switch Vcs-Browser to the cgit interface.
* Compile with large file support to avoid incompatibility with libmspack.
.
[ Scott Kitterman ]
* Add source:Version minimum version requirements for freshclam to clamav,
clamav-daemon, and clamav-milter
* Run wrap-and-sort to improve readability of debian/control and other
packaging files
.
[ Sebastian Andrzej Siewior ]
* import new upstream
* depend on libjson and enable libjson
* use external libmspack instead of the old modified internal copy of the
library (Closes: #675558).
Checksums-Sha1:
3f9e5b663b4eefd0f2b08ae016da72977acb1315 3069 clamav_0.98.5~beta1+dfsg-1.dsc
c5ddf5b93ce9049ecde719f3d8f8665d077e62e1 5766324
clamav_0.98.5~beta1+dfsg.orig.tar.xz
20f94c4f657909edfcc6273874ce24a677e47b35 241340
clamav_0.98.5~beta1+dfsg-1.debian.tar.xz
36216580ce55f93b64db7e59a05e6fe79cfe98c4 275936
clamav-base_0.98.5~beta1+dfsg-1_all.deb
98f8627524c8fa774c77ff06c630863e94433e7f 1266330
clamav-docs_0.98.5~beta1+dfsg-1_all.deb
bc509506579851a07e7474cd79978fe2b6306d4e 2597380
clamav-dbg_0.98.5~beta1+dfsg-1_i386.deb
8339400855a68af2e62c485babe59f12449b64ae 320572
clamav_0.98.5~beta1+dfsg-1_i386.deb
015a1ce34c24360377e3eedf4b0ec6130e24dbe2 237530
libclamav-dev_0.98.5~beta1+dfsg-1_i386.deb
5f4b2b35d02a041dee711f4bcf351329073565ac 4124816
libclamav6_0.98.5~beta1+dfsg-1_i386.deb
7c3f2d0e84db9f15152d0bdee857fa643818c5bb 436376
clamav-daemon_0.98.5~beta1+dfsg-1_i386.deb
524bb7f604138a2e564e7c6bc9ae5787d31ab7ea 3087986
clamav-testfiles_0.98.5~beta1+dfsg-1_all.deb
3119cf424db5a33e3571ba90a37f6a6b1ba223f2 344882
clamav-freshclam_0.98.5~beta1+dfsg-1_i386.deb
4bf38e71c7028a4cccc5e55c54dcfda026ea1847 384312
clamav-milter_0.98.5~beta1+dfsg-1_i386.deb
Checksums-Sha256:
3826ea82d20d108e0791e7a4e38f861cb17ff2cd683ef65bd2226be46495df55 3069
clamav_0.98.5~beta1+dfsg-1.dsc
ef0c7f6208d77f97806d143db2fb13ad108358c0e62a41e8a115074d7152b7d9 5766324
clamav_0.98.5~beta1+dfsg.orig.tar.xz
781fc75c6eb873238e1148ececf50943e19c7855bf5e70f852f4d2e0e1e3cee9 241340
clamav_0.98.5~beta1+dfsg-1.debian.tar.xz
c28f3e75f0c1a961c241896abade736bc2ecaffede4aab86b410a5d31d71af70 275936
clamav-base_0.98.5~beta1+dfsg-1_all.deb
71f21ef61a7799d6c7f9a2bf02eb2607d042466e49b5548991d669fb99ad0524 1266330
clamav-docs_0.98.5~beta1+dfsg-1_all.deb
da6b426b298155fd44133c0b9bc161cf0ef6b6aea4fb221a00275998f66fd22a 2597380
clamav-dbg_0.98.5~beta1+dfsg-1_i386.deb
1d0d0e98d6fc632b7584d7107ccaafeff0f6b057bd9241842bd66c1db6b16509 320572
clamav_0.98.5~beta1+dfsg-1_i386.deb
9155a5b252005625bf98e8979d42ffe8344e52fcac8b0de2d7e14d2a0f905adf 237530
libclamav-dev_0.98.5~beta1+dfsg-1_i386.deb
8c9170a9eaf10bc443706d7f1174b53e071cc9f87938dd12d285ca9b56b7cf07 4124816
libclamav6_0.98.5~beta1+dfsg-1_i386.deb
9060c0f090ad6d14afc8ba1b54a15603c612bbb84f893a22f488aac7ca252e3e 436376
clamav-daemon_0.98.5~beta1+dfsg-1_i386.deb
c553449e211e11ad6ee29512bf18a4fb8c7e5e12500ffe6acf41e8908cc4c0e8 3087986
clamav-testfiles_0.98.5~beta1+dfsg-1_all.deb
e25f274834ae18cc69955f24c43e9215d4591cd9437da1c6535182d1542ee533 344882
clamav-freshclam_0.98.5~beta1+dfsg-1_i386.deb
b0047ab47712d3aa1f5c4d0b3d727f0ea501d9f07d4a3fa24b1592a794f36a28 384312
clamav-milter_0.98.5~beta1+dfsg-1_i386.deb
Files:
db72a42e7787c0343a0b6d3a91b7289d 275936 utils optional
clamav-base_0.98.5~beta1+dfsg-1_all.deb
08ce43a9019b1b2aaad589c78b37c55e 1266330 doc optional
clamav-docs_0.98.5~beta1+dfsg-1_all.deb
58fba3d33ff4f24e178da3a0dd21e5b7 2597380 debug extra
clamav-dbg_0.98.5~beta1+dfsg-1_i386.deb
3d2dccdab4b1710a93a3e678bb26168d 320572 utils optional
clamav_0.98.5~beta1+dfsg-1_i386.deb
5558ec5cdc16f34783da8ab6e19426c8 237530 libdevel optional
libclamav-dev_0.98.5~beta1+dfsg-1_i386.deb
8d3df07e8adbc8a5636bef06946b5f1d 4124816 libs optional
libclamav6_0.98.5~beta1+dfsg-1_i386.deb
41d6ccf1387006aa8a61895b10c49929 436376 utils optional
clamav-daemon_0.98.5~beta1+dfsg-1_i386.deb
5385bc37a3b7eeb2750f3b70f42cff7b 3087986 utils optional
clamav-testfiles_0.98.5~beta1+dfsg-1_all.deb
438b20aa31f72439240b1765f3446023 344882 utils optional
clamav-freshclam_0.98.5~beta1+dfsg-1_i386.deb
d6e25d289a38c834887512174da7379e 384312 utils extra
clamav-milter_0.98.5~beta1+dfsg-1_i386.deb
934639b154cefe99d9c4a3945aeef133 3069 utils optional
clamav_0.98.5~beta1+dfsg-1.dsc
91bb79e31505da1496779221a07f9c17 5766324 utils optional
clamav_0.98.5~beta1+dfsg.orig.tar.xz
f81b84868f0baa9d6ff763ee6911b193 241340 utils optional
clamav_0.98.5~beta1+dfsg-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCAAGBQJT6tUPAAoJEHjX3vua1ZrxwoYP/3q8rmE1VIYnXviCqkPDya+C
0jZvzSy5aSemW+mLTytxM0dZAT++vlgpazN8g83/wnj0BUj1Shnr/dVwYInDEcRS
TNEZ5QzpR7jMJRK/fWEd2IxrIiFeo/pucCjVBuNMa44fHhDbLRU5FNmedgugmijl
m0ZGvVwvRXNXGhv1b/kg1VhFwvnEgfBz2cggyphwOXu+p9D9sR7sWC4Zx+QJWDh2
ArydZoJ7mIdWf0ZRUsq0pp1HbYmenSB3aeaKPTsNlwCdaWDFLypZn7eF5afwTwXR
IjBU6OYzI4neRrclALGzETJYuS3IJmf5+04pn+NR7I7n72v0kPKil41qlAuDITQ2
+tRe6z3OF4xZKO3CDZmF0NNl0q3DrgolNDUxg7Iu574f2LHmWMrbiSrqQQNVmVvV
H98UUJW3vtn7WfCCQr8qdMDHb48rZFp9cKX5l2YTZqVUJOOoQU6kZ0TndWyd3mMg
uLUMUZf6fH9rHwmp7v1r2iP8Ulv/MlElatWncLfwfKFVdgpTNg8VkEPOJCbvZLVF
ZB9vaEtoV/PJS59GNL9k2+N/S78ZqDVFt3l0RuUYkWI/x/6TprLRUSmbUuhih9NP
uKewNXhcLBCNEyiBRiPskeT4zXPOPhECAuf44FDtuSaDxGtxbx0sw0YtU/yba/tC
PvmoAIPYqI5UoJfHripH
=O9SU
-----END PGP SIGNATURE-----
--- End Message ---
_______________________________________________
Pkg-clamav-devel mailing list
[email protected]
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-clamav-devel