Package: clamav-daemon Version: 0.98.5+dfsg-3 Severity: grave Justification: renders package unusable Control: submitter -1 James Cloos <cl...@jhcloos.com> X-Debbugs-CC: James Cloos <cl...@jhcloos.com>
Forwarding the bug reported on the mailing list: https://lists.alioth.debian.org/pipermail/pkg-clamav-devel/2014-December/004884.html On 16.12.2014 15:59, James Cloos wrote:
Package: clamav-daemon Version: 0.98.5+dfsg-3 Severity: grave Justification: renders package unusable Starting Thursday night clamd died each night. After removing the clamav-unofficial-sigs cron job, last night clamd got stuck using all cpu. (800% on the 8-node box.) Either way that blocks all incoming mail. It is possible that this morning's bug was triggered by the logrotate cron job, given /etc/logrotate.d/clamav-daemon -- Package-specific info: --- configuration --- Checking configuration files in /etc/clamav Config file: clamd.conf ----------------------- LogFile = "/var/log/clamav/clamav.log" StatsHostID = "auto" StatsEnabled disabled StatsPEDisabled = "yes" StatsTimeout = "10" LogFileUnlock disabled LogFileMaxSize = "4294967295" LogTime = "yes" LogClean disabled LogSyslog disabled LogFacility = "LOG_LOCAL6" LogVerbose disabled LogRotate = "yes" ExtendedDetectionInfo = "yes" PidFile = "/var/run/clamav/clamd.pid" TemporaryDirectory disabled DatabaseDirectory = "/var/lib/clamav" OfficialDatabaseOnly disabled LocalSocket = "/var/run/clamav/clamd.ctl" LocalSocketGroup = "clamav" LocalSocketMode = "666" FixStaleSocket = "yes" TCPSocket disabled TCPAddr disabled MaxConnectionQueueLength = "15" StreamMaxLength = "26214400" StreamMinPort = "1024" StreamMaxPort = "2048" MaxThreads = "12" ReadTimeout = "180" CommandReadTimeout = "5" SendBufTimeout = "200" MaxQueue = "100" IdleTimeout = "30" ExcludePath disabled MaxDirectoryRecursion = "15" FollowDirectorySymlinks disabled FollowFileSymlinks disabled CrossFilesystems = "yes" SelfCheck = "3600" DisableCache disabled VirusEvent disabled ExitOnOOM disabled AllowAllMatchScan = "yes" Foreground disabled Debug disabled LeaveTemporaryFiles disabled User = "clamav" AllowSupplementaryGroups disabled Bytecode = "yes" BytecodeSecurity = "TrustSigned" BytecodeTimeout = "60000" BytecodeUnsigned disabled BytecodeMode = "Auto" DetectPUA disabled ExcludePUA disabled IncludePUA disabled AlgorithmicDetection = "yes" ScanPE = "yes" ScanELF = "yes" DetectBrokenExecutables disabled ScanMail = "yes" ScanPartialMessages disabled PhishingSignatures = "yes" PhishingScanURLs = "yes" PhishingAlwaysBlockCloak disabled PhishingAlwaysBlockSSLMismatch disabled PartitionIntersection disabled HeuristicScanPrecedence disabled StructuredDataDetection disabled StructuredMinCreditCardCount = "3" StructuredMinSSNCount = "3" StructuredSSNFormatNormal = "yes" StructuredSSNFormatStripped disabled ScanHTML = "yes" ScanOLE2 = "yes" OLE2BlockMacros disabled ScanPDF = "yes" ScanSWF = "yes" ScanArchive = "yes" ArchiveBlockEncrypted disabled ForceToDisk disabled MaxScanSize = "104857600" MaxFileSize = "26214400" MaxRecursion = "10" MaxFiles = "10000" MaxEmbeddedPE = "10485760" MaxHTMLNormalize = "10485760" MaxHTMLNoTags = "2097152" MaxScriptNormalize = "5242880" MaxZipTypeRcg = "1048576" MaxPartitions = "50" MaxIconsPE = "100" ScanOnAccess disabled OnAccessIncludePath disabled OnAccessExcludePath disabled OnAccessExcludeUID disabled OnAccessMaxFileSize = "5242880" DevACOnly disabled DevACDepth disabled DevPerformance disabled DevLiblog disabled DisableCertCheck disabled Config file: freshclam.conf --------------------------- StatsHostID disabled StatsEnabled disabled StatsTimeout disabled LogFileMaxSize = "4294967295" LogTime = "yes" LogSyslog disabled LogFacility = "LOG_LOCAL6" LogVerbose disabled LogRotate = "yes" PidFile = "/var/run/clamav/freshclam.pid" DatabaseDirectory = "/var/lib/clamav" Foreground disabled Debug disabled AllowSupplementaryGroups disabled UpdateLogFile = "/var/log/clamav/freshclam.log" DatabaseOwner = "clamav" Checks = "24" DNSDatabaseInfo = "current.cvd.clamav.net" DatabaseMirror = "db.local.clamav.net", "database.clamav.net" PrivateMirror = "10" MaxAttempts = "5" ScriptedUpdates = "yes" TestDatabases = "yes" CompressLocalDatabase disabled ExtraDatabase disabled DatabaseCustomURL disabled HTTPProxyServer disabled HTTPProxyPort disabled HTTPProxyUsername disabled HTTPProxyPassword disabled HTTPUserAgent disabled NotifyClamd = "/etc/clamav/clamd.conf" OnUpdateExecute disabled OnErrorExecute disabled OnOutdatedExecute disabled LocalIPAddress disabled ConnectTimeout = "30" ReceiveTimeout = "30" SubmitDetectionStats disabled DetectionStatsCountry disabled DetectionStatsHostID disabled SafeBrowsing disabled Bytecode = "yes" Config file: clamav-milter.conf ------------------------------- LogFile = "/var/log/clamav/clamav-milter.log" LogFileUnlock disabled LogFileMaxSize = "2097152" LogTime = "yes" LogSyslog disabled LogFacility = "LOG_LOCAL6" LogVerbose = "yes" LogRotate = "yes" PidFile = "/var/run/clamav/clamav-milter.pid" TemporaryDirectory = "/tmp" FixStaleSocket = "yes" MaxThreads = "10" ReadTimeout = "120" Foreground disabled User = "clamav" AllowSupplementaryGroups = "yes" MaxFileSize = "26214400" ClamdSocket = "unix:/var/run/clamav/clamd.ctl" MilterSocket = "local:/var/spool/postfix/clamav/clamav-milter.ctl" MilterSocketGroup = "clamav" MilterSocketMode = "666" LocalNet = "127.0.0.0/8", "208.68.39.189", "2001:4830:1662::/48", "2001:4830:1600:c::/64" OnClean = "Accept" OnInfected = "Quarantine" OnFail = "Defer" RejectMsg disabled AddHeader = "yes" ReportHostname disabled VirusAction disabled Chroot disabled Whitelist disabled SkipAuthenticated disabled LogInfected = "Full" LogClean = "Off" SupportMultipleRecipients disabled Software settings ----------------- Version: 0.98.5 Optional features supported: MEMPOOL IPv6 FRESHCLAM_DNS_FIX AUTOIT_EA06 BZIP2 LIBXML2 JSON RAR JIT Database information -------------------- Database directory: /var/lib/clamav [3rd Party] crdfam.clamav.hdb: 5000 sigs [3rd Party] securiteinfoelf.hdb: 1256 sigs [3rd Party] phish.ndb: 24658 sigs [3rd Party] bofhland_phishing_URL.ndb: 112 sigs [3rd Party] honeynet.hdb: 377 sigs [3rd Party] phishtank.ndb: 21028 sigs [3rd Party] winnow_extended_malware.hdb: 4176 sigs [3rd Party] jurlbl.ndb: 3810 sigs [3rd Party] winnow_malware.hdb: 3383 sigs [3rd Party] mbl.ndb: 0 sig [3rd Party] winnow.attachments.hdb: 710 sigs [3rd Party] winnow_malware_links.ndb: 7696 sigs [3rd Party] securiteinfohtml.hdb: 60487 sigs [3rd Party] rogue.hdb: 123 sigs [3rd Party] sanesecurity.ftm: 159 sigs [3rd Party] doppelstern.hdb: 1 sig [3rd Party] securiteinfooffice.hdb: 4264 sigs [3rd Party] securiteinfobat.hdb: 2600 sigs [3rd Party] securiteinfosh.hdb: 404 sigs [3rd Party] porcupine.ndb: 2469 sigs [3rd Party] bofhland_cracked_URL.ndb: 49036 sigs [3rd Party] securiteinfopdf.hdb: 6206 sigs [3rd Party] bofhland_malware_URL.ndb: 1098 sigs [3rd Party] spamattach.hdb: 23 sigs main.cld: version 55, sigs: 2424225, built on Tue Sep 17 14:57:28 2013 [3rd Party] securiteinfo.hdb: 327666 sigs [3rd Party] junk.ndb: 49067 sigs bytecode.cld: version 236, sigs: 43, built on Wed Feb 5 17:36:14 2014 [3rd Party] spamimg.hdb: 18 sigs [3rd Party] blurl.ndb: 704 sigs daily.cld: version 18853, sigs: 906510, built on Thu Apr 24 12:27:34 2014 [3rd Party] securiteinfodos.hdb: 4509 sigs [3rd Party] bofhland_malware_attach.hdb: 1327 sigs [3rd Party] winnow_bad_cw.hdb: 10000 sigs [3rd Party] scam.ndb: 12282 sigs Total number of signatures: 3935427 Platform information -------------------- uname: Linux 3.2.0-4-amd64 #1 SMP Debian 3.2.41-2+deb7u2 x86_64 OS: linux-gnu, ARCH: x86_64, CPU: x86_64 Full OS version: Debian GNU/Linux 8.0 (jessie) zlib version: 1.2.8 (1.2.8), compile flags: a9 Triple: x86_64-pc-linux-gnu CPU: x86-64, Little-endian platform id: 0x0a214f4f0804090201040902 Build information ----------------- GNU C: 4.9.2 (4.9.2) GNU C++: 4.9.2 (4.9.2) CPPFLAGS: -D_FORTIFY_SOURCE=2 CFLAGS: -g -O2 -fstack-protector-strong -Wformat -Werror=format-security -Wall -D_FILE_OFFSET_BITS=64 -fno-strict-aliasing -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE CXXFLAGS: LDFLAGS: -Wl,-z,relro Configure: '--build=x86_64-linux-gnu' '--prefix=/usr' '--includedir=/usr/include' '--mandir=/usr/share/man' '--infodir=/usr/share/info' '--sysconfdir=/etc' '--localstatedir=/var' '--disable-silent-rules' '--libexecdir=/usr/lib/clamav' '--disable-maintainer-mode' '--disable-dependency-tracking' 'CFLAGS=-g -O2 -fstack-protector-strong -Wformat -Werror=format-security -Wall -D_FILE_OFFSET_BITS=64' 'CPPFLAGS=-D_FORTIFY_SOURCE=2' 'CXXFLAGS=-g -O2 -fstack-protector-strong -Wformat -Werror=format-security -Wall -D_FILE_OFFSET_BITS=64' 'LDFLAGS=-Wl,-z,relro' '--with-dbdir=/var/lib/clamav' '--sysconfdir=/etc/clamav' '--disable-clamav' '--disable-unrar' '--enable-milter' '--enable-dns-fix' '--with-libjson' '--with-gnu-ld' '--with-system-tommath' '--without-included-ltdl' '-with-system-llvm=/usr/bin/llvm-config' '--with-systemdsystemunitdir=/lib/systemd/system' 'build_alias=x86_64-linux-gnu' sizeof(void*) = 8 Engine flevel: 79, dconf: 79 --- data dir --- total 271888 -rw-r--r-- 1 clamav clamav 85164 Dec 13 12:51 blurl.ndb -rw-r--r-- 1 clamav clamav 5325472 Dec 13 13:47 bofhland_cracked_URL.ndb -rw-r--r-- 1 clamav clamav 109244 Dec 12 23:48 bofhland_malware_URL.ndb -rw-r--r-- 1 clamav clamav 76224 Dec 13 08:47 bofhland_malware_attach.hdb -rw-r--r-- 1 clamav clamav 17088 Dec 12 23:48 bofhland_phishing_URL.ndb -rw-r--r-- 1 clamav clamav 345088 Feb 5 2014 bytecode.cld -rw-r--r-- 1 clamav clamav 362157 Dec 13 12:47 crdfam.clamav.hdb -rw-r--r-- 1 clamav clamav 58042368 Apr 24 2014 daily.cld -rw-r--r-- 1 clamav clamav 65 Jul 26 2013 doppelstern.hdb -rw-r--r-- 1 clamav clamav 22549 Feb 15 2012 honeynet.hdb -rw-r--r-- 1 clamav clamav 6151447 Dec 9 11:49 junk.ndb -rw-r--r-- 1 clamav clamav 379407 Dec 13 13:51 jurlbl.ndb -rw-r--r-- 1 clamav clamav 163468288 Sep 17 2013 main.cld -rw-r--r-- 1 clamav clamav 356 Jan 9 2014 mbl.ndb -rw-r--r-- 1 clamav clamav 1144 Apr 24 2014 mirrors.dat -rw-r--r-- 1 clamav clamav 3670721 Dec 11 13:49 phish.ndb -rw-r--r-- 1 clamav clamav 3130199 Dec 13 13:45 phishtank.ndb -rw-r--r-- 1 clamav clamav 301077 Dec 13 05:46 porcupine.ndb -rw-r--r-- 1 clamav clamav 9413 Dec 12 12:50 rogue.hdb -rw-r--r-- 1 clamav clamav 9952 Sep 3 12:31 sanesecurity.ftm -rw-r--r-- 1 clamav clamav 1867143 Dec 9 10:49 scam.ndb -rw-r--r-- 1 clamav clamav 26264069 Dec 13 03:13 securiteinfo.hdb -rw-r--r-- 1 clamav clamav 200405 Aug 21 2012 securiteinfobat.hdb -rw-r--r-- 1 clamav clamav 391274 Nov 28 2013 securiteinfodos.hdb -rw-r--r-- 1 clamav clamav 75040 Jan 21 2014 securiteinfoelf.hdb -rw-r--r-- 1 clamav clamav 4730756 Dec 13 03:16 securiteinfohtml.hdb -rw-r--r-- 1 clamav clamav 264154 Jan 15 2013 securiteinfooffice.hdb -rw-r--r-- 1 clamav clamav 468241 Aug 16 2012 securiteinfopdf.hdb -rw-r--r-- 1 clamav clamav 29520 Aug 21 2012 securiteinfosh.hdb -rw-r--r-- 1 clamav clamav 5689 Dec 12 10:30 sigwhitelist.ign2 -rw-r--r-- 1 clamav clamav 1602 Nov 21 14:51 spamattach.hdb -rw-r--r-- 1 clamav clamav 1148 Oct 28 16:51 spamimg.hdb drwxr-xr-x 2 clamav clamav 4096 Feb 1 2013 tmp -rw-r--r-- 1 clamav clamav 72798 Dec 13 02:45 winnow.attachments.hdb -rw-r--r-- 1 clamav clamav 918589 Dec 13 13:45 winnow_bad_cw.hdb -rw-r--r-- 1 clamav clamav 259932 Dec 13 02:45 winnow_extended_malware.hdb -rw-r--r-- 1 clamav clamav 207721 Dec 11 00:46 winnow_malware.hdb -rw-r--r-- 1 clamav clamav 1009425 Dec 13 02:45 winnow_malware_links.ndb -- System Information: Debian Release: 8.0 APT prefers unstable APT policy: (500, 'unstable'), (1, 'experimental') Architecture: amd64 (x86_64) Foreign Architectures: i386 Kernel: Linux 3.2.0-4-amd64 (SMP w/1 CPU core) Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/dash Init: sysvinit (via /sbin/init) Versions of packages clamav-daemon depends on: ii adduser 3.113+nmu3 ii clamav-base 0.98.5+dfsg-3 ii clamav-freshclam [clamav-data] 0.98.5+dfsg-3 ii debconf [debconf-2.0] 1.5.54 ii dpkg 1.17.22 ii init-system-helpers 1.22 ii libbz2-1.0 1.0.6-7+b2 ii libc6 2.19-13 ii libclamav6 0.98.5+dfsg-3 ii libjson-c2 0.11-4 ii libncurses5 5.9+20140913-1+b1 ii libssl1.0.0 1.0.1j-1 ii libsystemd0 215-8 ii libtinfo5 5.9+20140913-1+b1 ii lsb-base 4.1+Debian13+nmu1 ii procps 2:3.3.9-8 ii ucf 3.0030 ii zlib1g 1:1.2.8.dfsg-2+b1 Versions of packages clamav-daemon recommends: ii clamdscan 0.98.5+dfsg-3 Versions of packages clamav-daemon suggests: pn apparmor <none> pn clamav-docs <none> ii daemon 0.6.4-1 -- debconf information: clamav-daemon/TCPAddr: any clamav-daemon/LocalSocketMode: 666 clamav-daemon/Bytecode: true clamav-daemon/AddGroups: clamav-daemon/ScanOnAccess: false clamav-daemon/FollowFileSymlinks: false clamav-daemon/debconf: true clamav-daemon/ReadTimeout: 180 clamav-daemon/SelfCheck: 3600 clamav-daemon/ScanMail: true clamav-daemon/StatsTimeout: 10 clamav-daemon/ScanArchive: true clamav-daemon/StatsEnabled: false clamav-daemon/LogRotate: true clamav-daemon/MaxScriptNormalize: 5M clamav-daemon/FollowDirectorySymlinks: false clamav-daemon/StatsHostID: auto clamav-daemon/ScanSWF: true clamav-daemon/MaxThreads: 12 clamav-daemon/LocalSocketGroup: clamav clamav-daemon/LogTime: true clamav-daemon/DisableCertCheck: false clamav-daemon/MaxHTMLNormalize: 10M clamav-daemon/BytecodeSecurity: TrustSigned clamav-daemon/User: clamav clamav-daemon/OnAccessMaxFileSize: 5M clamav-daemon/LogSyslog: false clamav-daemon/TCPSocket: 3310 clamav-daemon/StreamMaxLength: 25 clamav-daemon/MaxConnectionQueueLength: 15 clamav-daemon/MaxHTMLNoTags: 2M clamav-daemon/MaxEmbeddedPE: 10M clamav-daemon/FixStaleSocket: true clamav-daemon/TcpOrLocal: UNIX clamav-daemon/LogFile: /var/log/clamav/clamav.log clamav-daemon/StatsPEDisabled: true clamav-daemon/ForceToDisk: false clamav-daemon/AllowAllMatchScan: true clamav-daemon/MaxDirectoryRecursion: 15 clamav-daemon/MaxZipTypeRcg: 1M clamav-daemon/LocalSocket: /var/run/clamav/clamd.ctl clamav-daemon/BytecodeTimeout: 60000
-- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org