> -Original Message-
> From: clamav-users-boun...@lists.clamav.net [mailto:clamav-users-
> boun...@lists.clamav.net] On Behalf Of Matt Olney
> Sent: Tuesday, October 23, 2012 2:58 PM
> To: ClamAV users ML
> Subject: Re: [clamav-users] Deep scanning of image files
>
> Maarten, can you help
Maarten, can you help us track this by adding a bug at
https://bugzilla.clamav.net/?
Thanks,
Matt
On Tue, Oct 23, 2012 at 2:18 PM, Maarten Broekman wrote:
> One thing I'm seeing more and more of is malware code (be it PHP or ASP)
> embedded after GIF headers. ClamAV sees the GIF header and tre
One thing I'm seeing more and more of is malware code (be it PHP or ASP)
embedded after GIF headers. ClamAV sees the GIF header and treats it
like an image (properly), but then ClamAV sees an HTML signature later
in the file. However, it doesn't do any normalization on that HTML
data. Would it b