[clamav-users] Major new false positive? BC.Exploit.CVE_2012_0184

2012-05-11 Thread Cedric Knight
Hi I'm seeing BC.Exploit.CVE_2012_0184 hit a wide variety of attachments as of 14:40 UTC this afternoon. Will submit a sample the usual way, but wanted to warn that it just seems to be quite extensive. (also possibly BC.Exploit.CVE_2012_0165). Anyone else seeing this? -- All best wishes, Ce

Re: [clamav-users] Major new false positive? BC.Exploit.CVE_2012_0184

2012-05-11 Thread Cedric Knight
On 11/05/12 17:14, Cedric Knight wrote: > Hi > > I'm seeing BC.Exploit.CVE_2012_0184 hit a wide variety of attachments as > of 14:40 UTC this afternoon. Will submit a sample the usual way, but > wanted to warn that it just seems to be quite extensive. (also > possibly BC.Exploit.CVE_2012_0165).

Re: [clamav-users] Major new false positive? BC.Exploit.CVE_2012_0184

2012-05-11 Thread Andrew Thompson
Cedric Knight wrote: > Hi > > I'm seeing BC.Exploit.CVE_2012_0184 hit a wide variety of attachments as > of 14:40 UTC this afternoon. Will submit a sample the usual way, but > wanted to warn that it just seems to be quite extensive. (also > possibly BC.Exploit.CVE_2012_0165). > > Anyone else

Re: [clamav-users] Major new false positive? BC.Exploit.CVE_2012_0184

2012-05-11 Thread Laurent CARON
On 11/05/2012 18:14, Cedric Knight wrote: Hi I'm seeing BC.Exploit.CVE_2012_0184 hit a wide variety of attachments as of 14:40 UTC this afternoon. Will submit a sample the usual way, but wanted to warn that it just seems to be quite extensive. (also possibly BC.Exploit.CVE_2012_0165). Anyone

Re: [clamav-users] Major new false positive? BC.Exploit.CVE_2012_0184

2012-05-11 Thread Joel Esler
Please run Freshclam. This has already been cleared up. Joel On May 11, 2012, at 12:14 PM, Cedric Knight wrote: > Hi > > I'm seeing BC.Exploit.CVE_2012_0184 hit a wide variety of attachments as > of 14:40 UTC this afternoon. Will submit a sample the usual way, but > wanted to warn that it jus

Re: [clamav-users] Major new false positive? BC.Exploit.CVE_2012_0184

2012-05-11 Thread Mark G Thomas
Hi, I'm also getting hits on BC.Exploit.CVE_2012_0165 today, which I believe are false positives. Mark On Fri, May 11, 2012 at 05:14:13PM +0100, Cedric Knight wrote: > Hi > > I'm seeing BC.Exploit.CVE_2012_0184 hit a wide variety of attachments as > of 14:40 UTC this afternoon. Will submit a s

Re: [clamav-users] Major new false positive? BC.Exploit.CVE_2012_0184

2012-05-11 Thread Alain Zidouemba
Thanks for the report Mark. Bytecode 174 and later fixes the problem. Please update your signatures. If any of you can share the samples that were falsely detected as BC.Exploit.CVE_2012_1865, please send them in at http://www.clamav.net/lang/en/sendvirus/ . Thanks! - Alain On Fri, May 11, 2012

Re: [clamav-users] Major new false positive? BC.Exploit.CVE_2012_0184

2012-05-11 Thread Alain Zidouemba
I meant BC.Exploit.CVE_2012_0165 :-) - Alain On Fri, May 11, 2012 at 12:56 PM, Alain Zidouemba wrote: > Thanks for the report Mark. Bytecode 174 and later fixes the problem. > Please update your signatures. If any of you can share the samples that > were falsely detected as BC.Exploit.CVE_2012_

[clamav-users] (no subject)

2012-05-11 Thread Andrew Thompson
Hello We were seeing a number of files being quarantined earlier with the reference BC.Exploit.CVE_2012_1847 FOUND and BC.Exploit.CVE_2012_0184 FOUND. The CVE numbers point to vulnerabilities found in Microsoft's Excel and Office suites. However, the files were not only excel spreadsheets but also

Re: [clamav-users] Major new false positive? BC.Exploit.CVE_2012_0184

2012-05-11 Thread Chris Conn
On 2012-05-11 12:14, Cedric Knight wrote: Hi I'm seeing BC.Exploit.CVE_2012_0184 hit a wide variety of attachments as of 14:40 UTC this afternoon. Will submit a sample the usual way, but wanted to warn that it just seems to be quite extensive. (also possibly BC.Exploit.CVE_2012_0165). Anyone

Re: [clamav-users] (no subject)

2012-05-11 Thread Joel Esler
Please run freshclam, an update has been pushed. Joel On May 11, 2012, at 11:40 AM, Andrew Thompson wrote: > > Hello > We were seeing a number of files being quarantined earlier with the reference > BC.Exploit.CVE_2012_1847 FOUND and BC.Exploit.CVE_2012_0184 FOUND. The CVE > numbers point to vu