Bug#888484: [Pkg-clamav-devel] Bug#888484: Processed (with 1 error): Re: Bug#888484: clamav: Security release 0.99.3 available

2018-01-27 Thread Sebastian Andrzej Siewior
On 27 January 2018 15:30:45 CET, Salvatore Bonaccorso wrote: >So "the remaining CVEs were not address yet" part. > I was referring to the Stretch release. The fd bug is fixed but not the CVEs. In the meantime I opened pu bugs for stable and oldstable. Sebastian

Bug#888484: [Pkg-clamav-devel] Processed (with 1 error): Re: Bug#888484: clamav: Security release 0.99.3 available

2018-01-27 Thread Salvatore Bonaccorso
Scott, Thank you. On Sat, Jan 27, 2018 at 03:12:31PM +, Scott Kitterman wrote: > > > On January 27, 2018 2:30:45 PM UTC, Salvatore Bonaccorso > wrote: > >Hi Scott, > > > >On Sat, Jan 27, 2018 at 02:05:59PM +, Scott Kitterman wrote: > >> fixed 888484

Bug#888484: [Pkg-clamav-devel] Processed (with 1 error): Re: Bug#888484: clamav: Security release 0.99.3 available

2018-01-27 Thread Scott Kitterman
On January 27, 2018 2:30:45 PM UTC, Salvatore Bonaccorso wrote: >Hi Scott, > >On Sat, Jan 27, 2018 at 02:05:59PM +, Scott Kitterman wrote: >> fixed 888484 0.99.3~beta2+dfsg-1 >> >> Everyone: >> >> Please leave the status of this bug to the package maintainers. >> We've

Bug#888484: [Pkg-clamav-devel] Processed (with 1 error): Re: Bug#888484: clamav: Security release 0.99.3 available

2018-01-27 Thread Salvatore Bonaccorso
Hi Scott, On Sat, Jan 27, 2018 at 02:05:59PM +, Scott Kitterman wrote: > fixed 888484 0.99.3~beta2+dfsg-1 > > Everyone: > > Please leave the status of this bug to the package maintainers. > We've checked and all the security issues in the new 0.99.3 release > were previously addressed in

Bug#888484: [Pkg-clamav-devel] Processed (with 1 error): Re: Bug#888484: clamav: Security release 0.99.3 available

2018-01-27 Thread Scott Kitterman
fixed 888484 0.99.3~beta2+dfsg-1 Everyone: Please leave the status of this bug to the package maintainers. We've checked and all the security issues in the new 0.99.3 release were previously addressed in the beta that's in testing/unstable. If you think this is incorrect, provide specific

Bug#888484: clamav: Security release 0.99.3 available

2018-01-26 Thread Bernhard Schmidt
Control: unfixed 888484 0.99.3~beta2+dfsg-1 Control: fixed 888511 0.99.3~beta2+dfsg-1 Hi >> >> We've have started seeing unexpected clamd crashes on a high-traffic mail >> system today, though I've been unable to isolate a test case. It's seems like >> too much of a coincidence that these

Bug#888484: clamav: Security release 0.99.3 available

2018-01-26 Thread Rob N ★
On Sat, Jan 27, 2018, at 11:08 AM, Sebastian Andrzej Siewior wrote: > I **think** the crashes you obsereved might be due to FD desc > issue. This> was fixed in Stretch by chance but not in Jessie. However the > remaining> CVEs were not addressed yet and I'm looking into it… Yes, I found this too

Bug#888484: clamav: Security release 0.99.3 available

2018-01-26 Thread Sebastian Andrzej Siewior
control: fixed -1 0.99.3~beta2+dfsg-1 On 2018-01-26 09:35:25 [+], Rob N wrote: > Package: clamav > Version: 0.99.2+dfsg-0+deb8u2 > Severity: important > > 0.99.3 has been released, see > http://blog.clamav.net/2018/01/clamav-0993-has-been-released.html. > > This fixed a number of overflow

Bug#888484: clamav: Security release 0.99.3 available

2018-01-26 Thread Bernhard Schmidt
Control: tags -1 security Control: severity -1 grave On Fri, Jan 26, 2018 at 09:35:25AM +, Rob N wrote: > Package: clamav > Version: 0.99.2+dfsg-0+deb8u2 > Severity: important > > 0.99.3 has been released, see > http://blog.clamav.net/2018/01/clamav-0993-has-been-released.html. > > This

Bug#888484: clamav: Security release 0.99.3 available

2018-01-26 Thread Rob N
Package: clamav Version: 0.99.2+dfsg-0+deb8u2 Severity: important 0.99.3 has been released, see http://blog.clamav.net/2018/01/clamav-0993-has-been-released.html. This fixed a number of overflow bugs, each of which has assigned CVE numbers due to the potential for denial of service. We've have