Bug#458532: Clamav vulnerable to symlink attack

2008-01-02 Thread Moritz Muehlenhoff
severity 458532 important thanks On Tue, Jan 01, 2008 at 02:01:00PM +, Neil McGovern wrote: > Package: clamav > Version: 0.90.1-3etch7 > Severity: critical > Tags: security This doesn't warrant an RC security bug. > Two new CVEs for clamav: > > Name: CVE-2007-6595 > Status: Candidate > URL:

Bug#458532: Clamav vulnerable to symlink attack

2008-01-01 Thread Nico Golde
Hi Neil, * Neil McGovern <[EMAIL PROTECTED]> [2008-01-01 15:26]: [...] > I'd say ignore CVE-2007-6596, as clamav also doesn't recognise > insert-random-proprietary-encoding-here either, so it's not really a > valid issue (imo). Isn't the problem with this that mailers exist that treat such conte

Bug#458532: Clamav vulnerable to symlink attack

2008-01-01 Thread Neil McGovern
Package: clamav Version: 0.90.1-3etch7 Severity: critical Tags: security Two new CVEs for clamav: Name: CVE-2007-6595 Status: Candidate URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6595 Reference: BUGTRAQ:20071229 TK53 Advisory #2: Multiple vulnerabilities in ClamAV Reference: UR