Hi,

I couldn't find any other relevant information on that, hence my
question.

I would like to have the clamav package in pkgsrc fixed (and I'm sure I
share that wish with all software packagers).  I saw that something that
really looks like a fix went into CVS ("Make sure the property tree
doesn't loop" in libclamav/ole2_extract.c), and it indeed fixes the
issue with the Word document posted on the Debian bug page
(http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=333566).

So, is that fix the real thing?  Are there other issues to consider, or
can it go into our package so that we don't have a vulnerable ClamAV
anymore?

-- 
Quentin Garnier - [EMAIL PROTECTED] - [EMAIL PROTECTED]
"When I find the controls, I'll go where I like, I'll know where I want
to be, but maybe for now I'll stay right here on a silent sea."
KT Tunstall, Silent Sea, Eye to the Telescope, 2004.

Attachment: pgpOl5l3qGsZl.pgp
Description: PGP signature

_______________________________________________
http://lurker.clamav.net/list/clamav-users.html

Reply via email to