[clamav-users] LibClamAV Warning: Don't know how to create filter for: Win.Downloader.LNKAgent-10001628-0

2023-05-16 Thread Ralf Hildebrandt via clamav-users
clamav-1.1.0-1: === May 16 10:00:23 de freshclam[864]: Tue May 16 10:00:23 2023 -> daily database available for update (local version: 26907, remote version: 26908) May 16 10:00:23 de freshclam[864]: WARNING: Tue May 16 10:00:23 2023 -> *** RESULT 200, SIZE: 7213 *** Why do

[clamav-users] Segfaults with database version 26908

2023-05-16 Thread Matthias Rieber
Hello List, since the update to version 26908 we observe a high amount of segfaults. As far as I can tell this happens in 0x7fdfd44c377d We use version 0.103.8+dfsg-0+deb11u1 on debian bullseye. Has anyone seen this, too? Best regards, Matthias __

Re: [clamav-users] [ext] Segfaults with database version 26908

2023-05-16 Thread Ralf Hildebrandt via clamav-users
* Matthias Rieber : > Hello List, > > since the update to version 26908 we observe a high amount of segfaults. Same here. > As far as I can tell this happens in > > 0x7fdfd44c377d > > We use version 0.103.8+dfsg-0+deb11u1 on debian bullseye. > > Has anyone seen this, too? I've seen this wit

Re: [clamav-users] [ext] Segfaults with database version 26908

2023-05-16 Thread Michael Orlitzky via clamav-users
On Tue, 2023-05-16 at 12:08 +0200, Ralf Hildebrandt via clamav-users wrote: > > > > > Has anyone seen this, too? > > I've seen this with 1.1.0-1 as well. Maybe they're related to the > "pattern issue" I posted a while ago > Me three. ___ Manage yo

Re: [clamav-users] [ext] Segfaults with database version 26908

2023-05-16 Thread Matthias Rieber
Hello, On Tue, 16 May 2023, Ralf Hildebrandt via clamav-users wrote: As far as I can tell this happens in 0x7fdfd44c377d We use version 0.103.8+dfsg-0+deb11u1 on debian bullseye. Has anyone seen this, too? I've seen this with 1.1.0-1 as well. Maybe they're related to the "pattern issue" I

Re: [clamav-users] Segfaults with database version 26908

2023-05-16 Thread Claudio Cuqui
Same here..same version, but compiled from source directly..and the same strange message when clamd is restarted: Starting clamd daemon: LibClamAV Warning: Don't know how to create filter for: Win.Downloader.LNKAgent-10001628-0 LibClamAV Warning: cli_ac_addpatt: cannot use filter for t

Re: [clamav-users] Segfaults with database version 26908

2023-05-16 Thread seena--- via clamav-users
Hi All,I have joined this list just know after see the reported issue  Clamd service keep crashing with the following error code  clamsmtp-clamd.service: main process exited, code=killed, status=11/SEGVKernel logs (dmesg) shows :clamd[4053]: segfault at 7f081a3530bf ip 7f0719f42960 sp 7f06b

Re: [clamav-users] Segfaults with database version 26908

2023-05-16 Thread David Raynor
Based on these reports we've started a take-back of the signature, so it will be dropped in the next daily CVD publish. We'll also analyze to see why this signature is triggering that behavior on some platforms. Dave R. On Tue, May 16, 2023 at 2:53 PM Claudio Cuqui wrote: > Same here..same

Re: [clamav-users] Segfaults with database version 26908

2023-05-16 Thread Arjen de Korte via clamav-users
Citeren David Raynor : Based on these reports we've started a take-back of the signature, so it will be dropped in the next daily CVD publish. We'll also analyze to see why this signature is triggering that behavior on some platforms. Here freshclam (1.1.0) does complain about this signature,

Re: [clamav-users] [ext] Segfaults with database version 26908

2023-05-16 Thread Micah Snyder (micasnyd) via clamav-users
All, For those who experience the crashes - is this happening when scanning any specific files with this signature in the database? If so, can you please share that with me directly? I see the same warning, but I haven't observed any crashes yet. I will continue to debug and try to figure out

Re: [clamav-users] LibClamAV Warning: Don't know how to create filter for: Win.Downloader.LNKAgent-10001628-0

2023-05-16 Thread Micah Snyder (micasnyd) via clamav-users
It appears that this warning was added by accident while fixing a bug shortly before release and no one noticed in review. We'll remove the warning in 1.1.1 and 1.2.0. Sorry for the confusion! Regards, Micah Micah Snyder ClamAV Development Talos Cisco Systems, Inc. _

Re: [clamav-users] End of life (EOL) policy change, 0.103 one year extension, 0.105 past end of life

2023-05-16 Thread Micah Snyder (micasnyd) via clamav-users
Hi Paul, Unlike Java or C#, Rust does not have any additional runtime library requirement. Regards, Micah Micah Snyder ClamAV Development Talos Cisco Systems, Inc. From: clamav-users on behalf of Paul Kosinski via clamav-users Sent: Monday, May 8, 2023 5:01

Re: [clamav-users] [ext] Segfaults with database version 26908

2023-05-16 Thread Micah Snyder (micasnyd) via clamav-users
The daily database has been updated to drop the offending signature. We're still investigating to understand what may cause a crash. I was able to see in https://github.com/Cisco-Talos/clamav/issues/923 that the crash may occur at database load time, and not during a scan. So that is a relief.

Re: [clamav-users] [ext] Segfaults with database version 26908

2023-05-16 Thread Mario Yorck via clamav-users
Here are some information: It crashes when specific files are scanned. However, but it is unlikely that the file contains the bad signature (but im not sure). I have a sample file, but with personal data that I cannot share. Yesterday I was able to reproduce the crash, but today I no longer have t