Bug#407409: clamav: Zip module failure with many PDF files

2007-01-18 Thread Ralf Hildebrandt
Package: clamav
Version: 0.90~rc2-2
Severity: normal


I'm using clamd from dansguardian to scan files our users are
downloading via our proxy servers. In general, this works great.

Unfortunately, clamd (and clamscan) seem to fail when given certain
PDF files.

I grepped for Zip module failure in the dansguardian's logs and
found these URLs:

% zgrep -h Zip module failure access.log* |awk '{print $5}'| sort | uniq

http://e-learning.studmed.unibe.ch/UroSurf/UroSurfdeutsch.pdf
http://users.path.ox.ac.uk/~scobbold/tig/tolweb/tolmec.pdf
http://www.kika.de/spielspass/basteln/stundenplaene/_dl/stundenplan_01.pdf
http://www.kika.de/spielspass/basteln/stundenplaene/_dl/stundenplan_02.pdf
http://www.prismacolor.de/download/prismacolor-preisliste2005-06.pdf
http://www.rth.info/luftrettung.pdf
http://www.ski-shop-charlottenburg.de/vertragsbedingungen.pdf

I picked the first URL, downloaded it without using the proxy and then
tried to clamscan it:

# clamscan UroSurfdeutsch.pdf
UroSurfdeutsch.pdf: Zip module failure

--- SCAN SUMMARY ---
Known viruses: 87232
Engine version: 0.90rc2
Scanned directories: 0
Scanned files: 1
Infected files: 0
Data scanned: 0.19 MB
Time: 1.758 sec (0 m 1 s)

#

It's unclear to me what the problem is.


-- System Information:
Debian Release: 4.0
  APT prefers testing
  APT policy: (990, 'testing'), (500, 'unstable'), (1, 'experimental')
Architecture: i386 (i686)
Shell:  /bin/sh linked to /bin/bash
Kernel: Linux 2.6.19.2
Locale: LANG=C, LC_CTYPE=C (charmap=ANSI_X3.4-1968)

Versions of packages clamav depends on:
ii  clamav-freshclam [clamav-dat 0.90~rc2-2  downloads clamav virus databases f
ii  libc62.3.6.ds1-8 GNU C Library: Shared libraries
ii  libclamav1   0.90~rc2-1  virus scanner library
ii  zlib1g   1:1.2.3-13  compression library - runtime

Versions of packages clamav recommends:
ii  arj   3.10.22-2  archiver for .arj files
ii  clamav-base   0.90~rc2-2 base package for clamav, an anti-v
ii  unzoo 4.4-5  zoo archive extractor

-- no debconf information


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#407409: clamav: Zip module failure with many PDF files

2007-01-18 Thread Stephen Gran
tags 407409 +confirmed
tags 407409 +fixed-upstream
thanks

This one time, at band camp, Ralf Hildebrandt said:
 Package: clamav
 Version: 0.90~rc2-2

Thanks very much for testing the experimental packages - it's good to
know that people are, as I have gotten actually very little feedback
about the upgrade process.

 Unfortunately, clamd (and clamscan) seem to fail when given certain
 PDF files.
 
 I grepped for Zip module failure in the dansguardian's logs and
 found these URLs:
 
 % zgrep -h Zip module failure access.log* |awk '{print $5}'| sort | uniq
 
 http://e-learning.studmed.unibe.ch/UroSurf/UroSurfdeutsch.pdf
 http://users.path.ox.ac.uk/~scobbold/tig/tolweb/tolmec.pdf
 http://www.kika.de/spielspass/basteln/stundenplaene/_dl/stundenplan_01.pdf
 http://www.kika.de/spielspass/basteln/stundenplaene/_dl/stundenplan_02.pdf
 http://www.prismacolor.de/download/prismacolor-preisliste2005-06.pdf
 http://www.rth.info/luftrettung.pdf
 http://www.ski-shop-charlottenburg.de/vertragsbedingungen.pdf

Upstream appears to have two bug reports about this:
https://wwws.clamav.net/bugzilla/show_bug.cgi?id=131
https://wwws.clamav.net/bugzilla/show_bug.cgi?id=43

And they say it is closed.  I will take a look and see if the patch is
small enough to backport, or if rc3 will release soon with the fix.

Take care,
-- 
 -
|   ,''`.Stephen Gran |
|  : :' :[EMAIL PROTECTED] |
|  `. `'Debian user, admin, and developer |
|`- http://www.debian.org |
 -


signature.asc
Description: Digital signature


Bug#407409: clamav: Zip module failure with many PDF files

2007-01-18 Thread Nigel Horne
 And they say it is closed.  I will take a look and see if the patch is
 small enough to backport, or if rc3 will release soon with the fix.

It was a trivial fix and should be backportalble if you so desire.

-Nigel



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#407409: clamav: Zip module failure with many PDF files

2007-01-18 Thread Stephen Gran
This one time, at band camp, Nigel Horne said:
  And they say it is closed.  I will take a look and see if the patch is
  small enough to backport, or if rc3 will release soon with the fix.
 
 It was a trivial fix and should be backportalble if you so desire.

Thank you for that.  I will look later today.  Do you think it's likely
that the fix will make it into rc3 or 0.90 final?

Thanks again,
-- 
 -
|   ,''`.Stephen Gran |
|  : :' :[EMAIL PROTECTED] |
|  `. `'Debian user, admin, and developer |
|`- http://www.debian.org |
 -


signature.asc
Description: Digital signature


Bug#407409: clamav: Zip module failure with many PDF files

2007-01-18 Thread Nigel Horne

Stephen Gran wrote:


Thank you for that.  I will look later today.  Do you think it's likely
that the fix will make it into rc3 or 0.90 final?


I hope it will be in 0.90rc3 but I TK will be able to verify that.


--
Nigel Horne. Arranger, Adjudicator, Band Trainer, Composer, Tutor, Typesetter.
NJH Music, Barnsley, UK.  ICQ#20252325
[EMAIL PROTECTED] http://www.bandsman.co.uk
begin:vcard
fn:Nigel Horne
n:Horne;Nigel
org:NJH Music
email;internet:[EMAIL PROTECTED]
tel;fax:+44 870 705 9334
note:Skype: nigelhorne
x-mozilla-html:FALSE
version:2.1
end:vcard



Bug#407409: clamav: Zip module failure with many PDF files

2007-01-18 Thread Stephen Gran
This one time, at band camp, Nigel Horne said:
  And they say it is closed.  I will take a look and see if the patch is
  small enough to backport, or if rc3 will release soon with the fix.
 
 It was a trivial fix and should be backportalble if you so desire.

It looks like I may have spoken too soon.  I see:
Revision 1.56 
Sun Oct 22 10:23:26 2006 UTC by njh 
Handle ASCII85 encoded Flated objects

Which is what I naively assumed was the problem.

However, that code is already in rc2.  So, just to be sure, I did an
update of clamav-devel from cvs, and got:

[EMAIL PROTECTED]:~/clamav-devel$ libtool --mode=execute clamscan/clamscan 
~/UroSurfdeutsch.pdf 
/home/steve/UroSurfdeutsch.pdf: Zip module failure

--- SCAN SUMMARY ---
Known viruses: 87232
Engine version: devel-20070118
Scanned directories: 0
Scanned files: 1
Infected files: 0
Data scanned: 0.19 MB
Time: 1.690 sec (0 m 1 s)

So it looks like this is a seperate problem.  Can you take a look at it
when you have a moment, or would you like me to open a new report in
bugzilla first?

Thanks,
-- 
 -
|   ,''`.Stephen Gran |
|  : :' :[EMAIL PROTECTED] |
|  `. `'Debian user, admin, and developer |
|`- http://www.debian.org |
 -


signature.asc
Description: Digital signature


Bug#407409: clamav: Zip module failure with many PDF files

2007-01-18 Thread Nigel Horne

Stephen Gran wrote:


So it looks like this is a seperate problem.  Can you take a look at it
when you have a moment, or would you like me to open a new report in
bugzilla first?


Yes, please open in bugzilla.


Thanks,



--
Nigel Horne. Arranger, Adjudicator, Band Trainer, Composer, Tutor, Typesetter.
NJH Music, Barnsley, UK.  ICQ#20252325
[EMAIL PROTECTED] http://www.bandsman.co.uk
begin:vcard
fn:Nigel Horne
n:Horne;Nigel
org:NJH Music
email;internet:[EMAIL PROTECTED]
tel;fax:+44 870 705 9334
note:Skype: nigelhorne
x-mozilla-html:FALSE
version:2.1
end:vcard