Hi, I couldn't find any other relevant information on that, hence my question.
I would like to have the clamav package in pkgsrc fixed (and I'm sure I share that wish with all software packagers). I saw that something that really looks like a fix went into CVS ("Make sure the property tree doesn't loop" in libclamav/ole2_extract.c), and it indeed fixes the issue with the Word document posted on the Debian bug page (http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=333566). So, is that fix the real thing? Are there other issues to consider, or can it go into our package so that we don't have a vulnerable ClamAV anymore? -- Quentin Garnier - [EMAIL PROTECTED] - [EMAIL PROTECTED] "When I find the controls, I'll go where I like, I'll know where I want to be, but maybe for now I'll stay right here on a silent sea." KT Tunstall, Silent Sea, Eye to the Telescope, 2004.
pgpOl5l3qGsZl.pgp
Description: PGP signature
_______________________________________________ http://lurker.clamav.net/list/clamav-users.html