Hello,

I'm trying clamav 0.51 and very often I see things like these:

ERROR: Can't create 
/tmp/77e445760991fdd6/=?koi8-r?B?+s/dsfkhskadjfhskdajfhksdjfhkasdjfhkjsd?=

Also I consider the following a security problem_ with --mbox
option:

ERROR: Can't create /tmp/680d5860c193cdcf/../aaaNew.bat

(I specifically made such alteration to usual Klez thing:

Content-Type: audio/x-midi;
        name=../aaaNew.bat
Content-Transfer-Encoding: base64
Content-ID: <OP43652RN40a1cr>


to check this. And - now aaaNew.bat is sitting in /tmp

My suggestion is to use digested file name and NEVER try to write as a
file name letter's contents. (Of course, each letter should fadd some
serial number - so files with equal names will be processed properly.
Some hash like sha or md5 is up to the task, IMHO.)

Also, I worry why temp. directories aren't deleted after the task is done.


Sincerely yours, Roman A.Suzi
-- 
 - Petrozavodsk - Karelia - Russia - mailto:[EMAIL PROTECTED] -
 


---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]




Reply via email to