Re: ClamAV vulnerability

2005-09-26 Thread Steve Kemp
On Mon, Sep 26, 2005 at 05:36:27AM -0700, P PRABHU wrote: > Any fix for the latest ClamAV buffer overflow in the > file "upx.c" vulnerability. Currently .deb based > version is 0.84-2.sarge.2 . Is this version subject to > this vulnerability ?? If so any fix will be released A DSA is pending, a

Re: ClamAV vulnerability

2005-09-26 Thread Willi Mann
P PRABHU schrieb: Hai Any fix for the latest ClamAV buffer overflow in the file "upx.c" vulnerability. Currently .deb based version is 0.84-2.sarge.2 . Is this version subject to this vulnerability ?? Yes. See: http://spohr.debian.org/~joeyh/stable-security.html If so any fix will be rele

ClamAV vulnerability

2005-09-26 Thread P PRABHU
Hai Any fix for the latest ClamAV buffer overflow in the file "upx.c" vulnerability. Currently .deb based version is 0.84-2.sarge.2 . Is this version subject to this vulnerability ?? If so any fix will be released ?? Refer : http://www.securityfocus.com/bid/14867 Thanks Prabhu