Re: [clamav-users] Html.Exploit.CVE_2017_0141-6003839-0 FP's

2017-03-16 Thread Christopher Marczewski
Al, Thanks for the report. In the interim, I'll pass that link along so we can get a fix in as soon as possible. On Wed, Mar 15, 2017 at 10:55 PM, Al Varnell wrote: > There have now been three ClamXav user reports of > Html.Exploit.CVE_2017_0141-6003839-0, most, if not all involving browser > c

[clamav-users] CentOS 7 fanotify and Clamd

2017-03-16 Thread Nick Couchman
I'm trying to get on-access scanning working in clamav on CentOS 7. I'm running CentOS 7.3, kernel 3.10.0-514.6.2.el7.x86_64, and can confirm that the kernel is compiled with fanotify support: # grep -i fanotify /boot/config-3.10.0-514.6.2.el7.x86_64 CONFIG_FANOTIFY=y CONFIG_FANOTIFY_ACCESS_PERMI

Re: [clamav-users] Html.Exploit.CVE_2017_0141-6003839-0 FP's

2017-03-16 Thread Al Varnell
Christopher, Thanks for giving a hand. Several more reports this morning. ClamXav has added it to ClamXav.ign2. Now I see there are reports concerning a different signature for the same CVE when accessing https://wordpress.org and Html.Exploit.CVE_2017_0141-6010301-0, which I can verify. -Al