This one time, at band camp, Florian Weimer said: > * Stephen Gran: > > > So, it looks like this is the patch that fixes the infinite loop. > > Comments, etc, appreciated. Security folks, does this look to you like > > it does the job, and can I upload it for sarge? > > This is basically a reimplementation of mpz_setbit and friends. If > GMP is a mandatory build dependency of ClamAV, these functions should > probably be used instead.
I have discussed this with upstream, and they don't want to make gmp mandatory (right now it's an option to configure). I have confirmed that it no longer loops on the file in question. Do we want to go ahead with this, or no? I am ready for an upload if so. Thanks, -- ----------------------------------------------------------------- | ,''`. Stephen Gran | | : :' : [EMAIL PROTECTED] | | `. `' Debian user, admin, and developer | | `- http://www.debian.org | -----------------------------------------------------------------
signature.asc
Description: Digital signature