[Clamav-users] NULL dereference in clamav-milter 0.95

2009-03-30 Thread aCaB
Hi,

A bug has been reported affecting clamav-milter 0.95.
If LogInfected is set to Full and the message being processed lacks
either the Subject, Message-ID or Date headers a NULL pointer is
dereferenced which will cause the program to be aborted.

For SVN users the issue is fixed in r4991.
For Stable users, the issue will be fixed in the upcoming 0.95.1 version
which is to be released soon. In the meantime it is recommended to set
LogInfected to Off (the default) or Basic in clamav-milter.conf.

For full details see:
https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1522

Thanks,
-aCaB
___
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml


Re: [Clamav-users] NULL dereference in clamav-milter 0.95

2009-03-30 Thread James Kosin
aCaB wrote:
 Hi,
 
 A bug has been reported affecting clamav-milter 0.95.
 If LogInfected is set to Full and the message being processed lacks
 either the Subject, Message-ID or Date headers a NULL pointer is
 dereferenced which will cause the program to be aborted.
 
 For SVN users the issue is fixed in r4991.
 For Stable users, the issue will be fixed in the upcoming 0.95.1 version
 which is to be released soon. In the meantime it is recommended to set
 LogInfected to Off (the default) or Basic in clamav-milter.conf.
 
 For full details see:
 https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1522
 
 Thanks,
 -aCaB

Thanks,

Was the patch provided in the link the only change to fix the issue?
Or were other files affected?

Thanks again,
James



signature.asc
Description: OpenPGP digital signature
___
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml

Re: [Clamav-users] NULL dereference in clamav-milter 0.95

2009-03-30 Thread aCaB
James Kosin wrote:
 Was the patch provided in the link the only change to fix the issue?
 Or were other files affected?

Hi James,
The patch from  Dimitar Pashev in the bugzilla should work ok.
The official patch in svn is a bit different. I've attached it for your
convenience to the same bug. Grab it here:
https://wwws.clamav.net/bugzilla/attachment.cgi?id=991

--aCaB
___
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml