Package: clamav-daemon
Severity: important
Tags: security upstream

The command VERSION, sent to the daemon, makes the daemon open the
database file on disk and output the version of the database file on
disk. This might, however, be a version different to the one that is
actually loaded.

In my opinion, VERSION should return the version of the database that
the daemon is actually using. Since this is an upstream issue, I am
tagging the bug appropriately.

The security tag is used because this issue might lead to people
thinking they are secure because VERSION reports the current database
release. The daemon might actually be using an older version.

Greetings
Marc

-- System Information:
Debian Release: testing/unstable
  APT prefers unstable
  APT policy: (500, 'unstable'), (500, 'stable')
Architecture: i386 (i686)
Shell:  /bin/sh linked to /bin/bash
Kernel: Linux 2.6.12.2-zgsrv
Locale: LANG=C, LC_CTYPE=de_DE (charmap=ISO-8859-1)


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to