Re: [clamav-users] clamav on rhel 6.7 x32

2021-04-13 Thread Joel Esler (jesler) via clamav-users
I wouldn’t install something that old. I would go ahead and move on. Sent from my  iPhone On Apr 13, 2021, at 18:29, Eero Volotinen wrote:  Hi, I think that installing following files will fix your problem.

[clamav-users] clamav on rhel 6.7 x32

2021-04-13 Thread Eero Volotinen
Hi, I think that installing following files will fix your problem. https://archives.fedoraproject.org/pub/archive/epel/6/i386/Packages/c/clamav-0.100.3-1.el6.i686.rpm https://archives.fedoraproject.org/pub/archive/epel/6/i386/Packages/c/clamav-db-0.100.3-1.el6.i686.rpm Please test first on your

Re: [clamav-users] Unable to Update

2021-04-13 Thread Andrew C Aitchison via clamav-users
On Tue, 13 Apr 2021, j via clamav-users wrote: I've been getting the following message'WARNING: getpatch: Can't download daily-26093.cdiff from database.clamav.net WARNING: getpatch: Can't download daily-26093.cdiff from database.clamav.net WARNING: getpatch: Can't download

Re: [clamav-users] Last ClamAV compatible with x32

2021-04-13 Thread Eero Volotinen
Looks like there is still supported clam av available from epel vault: https://archives.fedoraproject.org/pub/archive/epel/6/i386/Packages/c/clamav-0.100.3-1.el6.i686.rpm Eero On Tue, Apr 13, 2021 at 7:25 AM Paul Kosinski via clamav-users < clamav-users@lists.clamav.net> wrote: > I have

Re: [clamav-users] Unable to Update

2021-04-13 Thread Eero Volotinen
Hi, What is your clamav/freshclam version. Eero On Tue, Apr 13, 2021 at 10:46 PM j via clamav-users < clamav-users@lists.clamav.net> wrote: > I've been getting the following message'WARNING: getpatch: Can't > download daily-26093.cdiff from database.clamav.net > WARNING: getpatch: Can't

[clamav-users] Unable to Update

2021-04-13 Thread j via clamav-users
I've been getting the following message'WARNING: getpatch: Can't download daily-26093.cdiff from database.clamav.net WARNING: getpatch: Can't download daily-26093.cdiff from database.clamav.net WARNING: getpatch: Can't download daily-26093.cdiff from database.clamav.net WARNING: Can't

Re: [clamav-users] Please clarify ClamAV 0.103.2 security patch release

2021-04-13 Thread Damian via clamav-users
Hi, the blog [1] is inconsistent with the CVEs descriptions for CVE-2021-1404 and -1405. This makes it unclear which versions are affected by which CVE. Can you fix the blog please? I see the blog has been corrected, thank you. Furthermore, can you please confirm that the "buffer overread in

Re: [clamav-users] Heuristics.Phishing.Email.SpoofedDomain...

2021-04-13 Thread G.W. Haywood via clamav-users
Hi there, On Tue, 13 Apr 2021, Robert Kudyba wrote: So I still don't know what "queue_id" is. Try the command mailq and look in the Sendmail docs. The queue ID is just the filename in the mail queue directory without the first two characters. For each message in the queue there are two

Re: [clamav-users] Heuristics.Phishing.Email.SpoofedDomain...

2021-04-13 Thread Robert Kudyba
> > > Also, with clamav-milter and sendmail. I see that the headers of > quarantined messages go to /var/spool/mqueue with root:smmsp owner/group > permissions and the header of the email starts with hf whilst the body of > the message starts with df. So the message in question looks like this: >

[clamav-users] ClamAV MD5 sum based whitelists (*.fp) don’t work in Ubuntu MATE 20.04.2

2021-04-13 Thread Pavel Řezníček
Hello folks, I am new to this mailing list. I’ve got a question related to ClamAV’s .fp files. Since I am a Ubuntu user, I asked my question on askubuntu.com: https://askubuntu.com/questions/1331021/clamav-md5-sum-based-whitelists-fp-don-t-work-in-ubuntu-mate-20-04-2. Got directed to a

Re: [clamav-users] Heuristics.Phishing.Email.SpoofedDomain...

2021-04-13 Thread eric-list
Robert, > From: clamav-users On Behalf Of > Robert Kudyba > Sent: Tuesday, April 13, 2021 10:40 AM > To: ClamAV users ML > Cc: G.W. Haywood > Subject: Re: [clamav-users] Heuristics.Phishing.Email.SpoofedDomain... > > I'm seeing a FP from a Delta Airlines email. > > Also, with clamav-milter

Re: [clamav-users] Heuristics.Phishing.Email.SpoofedDomain...

2021-04-13 Thread Robert Kudyba
I'm seeing a FP from a Delta Airlines email. Also, with clamav-milter and sendmail. I see that the headers of quarantined messages go to /var/spool/mqueue with root:smmsp owner/group permissions and the header of the email starts with hf whilst the body of the message starts with df. So the

[clamav-users] Please clarify ClamAV 0.103.2 security patch release

2021-04-13 Thread Damian via clamav-users
Hi, the blog [1] is inconsistent with the CVEs descriptions for CVE-2021-1404 and -1405. This makes it unclear which versions are affected by which CVE. Can you fix the blog please? Furthermore, can you please confirm that the "buffer overread in PDF parser" issue (CVE-2021-1405 according