*** This bug is a security vulnerability ***

You have been subscribed to a public security bug by Seth Arnold (seth-arnold):

My system showed unusually high memory and swap usage for a few weeks,
also occasional lags in situations when it was always brisk before.  I
naturally ran clamscan to check.  Pnscan was flagged as containing the
malware.  I removed and purged pnscan, and continued to scan for
anything else out of line.  Saw nothing else, and rebooted.  Memory and
swap usage was normal for several hours.  Then I reinstalled pnscan from
the repository.  Clamscan reported Unix.Tool.Pnscan-8031486-0 in pnscan
again.  So I removed and purged pnscan again.

I recognize that clamscan could be misleading here, but I never saw this
report before, and it's clear that my memory and swap issues haven't
returned.

I'm going to suggest this is a security vulnerability, even though the
clamscan result might be misleading.

lsb_release -rd
Description:    Ubuntu 20.04.4 LTS
Release:        20.04

uname -a
Linux ryzen7 5.4.0-107-lowlatency #121-Ubuntu SMP PREEMPT Thu Mar 24 16:45:08 
UTC 2022 x86_64 x86_64 x86_64 GNU/Linux

pnscan 1.12+git20180612-2

ProblemType: Bug
DistroRelease: Ubuntu 20.04
Package: pnscan 1.12+git20180612-2
ProcVersionSignature: Ubuntu 5.4.0-107.121-lowlatency 5.4.174
Uname: Linux 5.4.0-107-lowlatency x86_64
ApportVersion: 2.20.11-0ubuntu27.23
Architecture: amd64
CasperMD5CheckResult: skip
CurrentDesktop: KDE
Date: Tue Apr 12 20:48:45 2022
InstallationDate: Installed on 2012-12-03 (3417 days ago)
InstallationMedia: Kubuntu 12.10 "Quantal Quetzal" - Release amd64 (20121017.1)
ProcEnviron:
 PATH=(custom, no user)
 XDG_RUNTIME_DIR=<set>
 LANG=en_US.UTF-8
 SHELL=/bin/bash
SourcePackage: pnscan
UpgradeStatus: Upgraded to focal on 2020-04-29 (713 days ago)

** Affects: pnscan (Ubuntu)
     Importance: Undecided
         Status: New


** Tags: amd64 apport-bug focal
-- 
Clamscan reports Unix.Tool.Pnscan-8031486-0 in 1.12+git20180612-2 pnscan version
https://bugs.launchpad.net/bugs/1968806
You received this bug notification because you are a member of Ubuntu Bugs, 
which is subscribed to the bug report.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to