Re: [clamav-users] [Clamav-users] Clamscan detected a UNIX.Exploit.CVE_2010_3301

2012-10-22 Thread AndySH
Hi Alain, After recent update, clamav didn't reported it as a UNIX.Exploit.CVE_2010_3301 again. Downloading daily-15491.cdiff [100%] Downloading daily-15492.cdiff [100%] daily.cld updated (version: 15492, sigs: 277603, f-level: 63, builder: guitar) $ clamscan -r /var/lib/rpm --infected ---

Re: [clamav-users] [Clamav-users] Clamscan detected a UNIX.Exploit.CVE_2010_3301

2012-10-22 Thread Christoph Mitasch
Hi David, thanks for the response. With todays antivirus definitions it isn't detected anymore. Regards, Christoph - Ursprüngliche Mail - > Von: "David Raynor" > An: "ClamAV users ML" > Gesendet: Montag, 22. Oktober 2012 17:56:21 > Betreff: Re: [

Re: [clamav-users] [Clamav-users] Clamscan detected a UNIX.Exploit.CVE_2010_3301

2012-10-22 Thread David Raynor
On Mon, Oct 22, 2012 at 4:35 AM, Christoph Mitasch < cmita...@thomas-krenn.com> wrote: > Hello, > > I have the same problem since a few days. > > When I try to submit it as False Positive, it says it is not recognized by > ClamAV. > http://www.clamav.net/lang/en/sendvirus/submit-fp/ > > But on the

Re: [clamav-users] [Clamav-users] Clamscan detected a UNIX.Exploit.CVE_2010_3301

2012-10-22 Thread Christoph Mitasch
Hello, I have the same problem since a few days. When I try to submit it as False Positive, it says it is not recognized by ClamAV. http://www.clamav.net/lang/en/sendvirus/submit-fp/ But on the commandline it is definitely reported. host:~# tail -f /var/log/clamav/freshclam.log Mon Oct 22 10:1

Re: [clamav-users] [Clamav-users] Clamscan detected a UNIX.Exploit.CVE_2010_3301

2012-10-20 Thread Alain Zidouemba
Please submit a false positive report here: http://www.clamav.net/lang/en/sendvirus/submit-fp/ We will analyze your sample and get back to you as soon as possible. Thanks, - Alain ___ Help us build a comprehensive ClamAV guide: visit http://wiki.clamav

[clamav-users] [Clamav-users] Clamscan detected a UNIX.Exploit.CVE_2010_3301

2012-10-20 Thread AndySH
Hi, When I scan my systems I found the following, /var/lib/rpm/Packages: UNIX.Exploit.CVE_2010_3301 FOUND I understand that new signature was added on the recent daily.cld updated (version: 15479). Currently the system is using Centos 6.2 kernel 2.6.32-220.7.1.el6.x86_64. I believe they should