Bug#989549: clamav-daemon: any local user can shut clamd down via control socket

2024-02-08 Thread Stephane Chazelas
FYI, bugzilla.clamav.net has been discontinued. New upstreams bugs: https://github.com/Cisco-Talos/clamav/issues/1169 (also https://github.com/Cisco-Talos/clamav/issues/347 https://github.com/Cisco-Talos/clamav/issues/922)

Bug#989549: clamav-daemon: any local user can shut clamd down via control socket

2021-06-29 Thread Sebastian Andrzej Siewior
forwarded -1 https://bugzilla.clamav.net/show_bug.cgi?id=12782 Sebastian

Bug#989549: clamav-daemon: any local user can shut clamd down via control socket

2021-06-07 Thread Stephane Chazelas
Some additional notes, from discussion on the Ubuntu bugs: 1. dpkg-reconfigure dialogs say in the first dialog: "The ClamAV suite won't work if it isn't configured". However, that dialog is not displayed upon install, and except for https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=97

Bug#989549: clamav-daemon: any local user can shut clamd down via control socket

2021-06-07 Thread Stephane Chazelas
Package: clamav-daemon Version: 0.103.2+dfsg-2 Severity: important Hello, this is spawned off https://bugs.launchpad.net/ubuntu/+source/clamav/+bug/1930393 where I reported the same bug for Ubuntu. Also affects Debian. It's a (non-critical) security vulnerability but the issue has already made pu