This one time, at band camp, Florian Weimer said:
> * Stephen Gran:
> 
> > So, it looks like this is the patch that fixes the infinite loop.
> > Comments, etc, appreciated.  Security folks, does this look to you like
> > it does the job, and can I upload it for sarge?
> 
> This is basically a reimplementation of mpz_setbit and friends.  If
> GMP is a mandatory build dependency of ClamAV, these functions should
> probably be used instead.

I have discussed this with upstream, and they don't want to make gmp
mandatory (right now it's an option to configure).  I have confirmed
that it no longer loops on the file in question.  Do we want to go ahead
with this, or no?  I am ready for an upload if so.

Thanks,
-- 
 -----------------------------------------------------------------
|   ,''`.                                            Stephen Gran |
|  : :' :                                        [EMAIL PROTECTED] |
|  `. `'                        Debian user, admin, and developer |
|    `-                                     http://www.debian.org |
 -----------------------------------------------------------------

Attachment: signature.asc
Description: Digital signature

Reply via email to