Re: [clamav-users] FW: APPLE-SA-2011-03-21-1 Mac OS X v10.6.7 and Security Update 2011-001

2011-03-29 Thread Russ Tyndall

On Mar 27, 2011, at 2:31 AM, Al Varnell wrote:

 Some Mac users will recall that several months back we discussed the bzip2
 bug and I filed a bug report with Apple when it wasn't included in their
 previous updates back in November.  They acknowledged they were working on
 it and promised it would be out shortly.  Last Monday they posted updates to
 both Mac OS X 10.5.8 and 10.6.6 which purports to fix the bug (forwarded
 below).

For older machines (10.4) what is the best way to update bzip2?

Do I need to put MacPorts on every machine?  Or can updated bzip2 files be 
manually installed? Obviously, I am going to have to go third-party.

If bzip2 is not updated, will clamd be unstable?

Thanks.

-
Russ Tyndall
Wake Forest, NC



___
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml


Re: [clamav-users] FW: APPLE-SA-2011-03-21-1 Mac OS X v10.6.7 and Security Update 2011-001

2011-03-29 Thread TR Shaw

On Mar 29, 2011, at 1:06 PM, Al Varnell wrote:

 On 3/29/11 6:29 AM, Russ Tyndall fitz...@redshanksoftware.com wrote:
 
 
 On Mar 27, 2011, at 2:31 AM, Al Varnell wrote:
 
 Some Mac users will recall that several months back we discussed the bzip2
 bug and I filed a bug report with Apple when it wasn't included in their
 previous updates back in November.  They acknowledged they were working on
 it and promised it would be out shortly.  Last Monday they posted updates to
 both Mac OS X 10.5.8 and 10.6.6 which purports to fix the bug (forwarded
 below).
 
 For older machines (10.4) what is the best way to update bzip2?
 
 Mac OS X 10.4 probably has bigger security issues for you than bzip2 as
 there have been no updates since Sep 2009.
 
 Do I need to put MacPorts on every machine?  Or can updated bzip2 files be
 manually installed? Obviously, I am going to have to go third-party.
 
 I can't think of any reason you couldn't just download and compile the
 source from http://bzip.org/ and install all the files for v1.0.6.  I
 don't really know what the OS uses bzip2 for, other than decompressing .bz2
 files that it runs across, but there could potentially be OS compatibility
 issues.  I'm aware of several folks who have been using v1.0.6 since it came
 out, at least one of whom is running 10.4 and have not reported having any
 issues.

Al,

The problem is that the make for dynamic libraries doesn't work out of the box 
so even if you compile the static version clam will link with the old dynamic 
lib.

Tom
___
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml


Re: [clamav-users] FW: APPLE-SA-2011-03-21-1 Mac OS X v10.6.7 and Security Update 2011-001

2011-03-29 Thread Rick Pim

   I can't think of any reason you couldn't just download and compile the
   source from http://bzip.org/ and install all the files for v1.0.6.

i can't speak for MacOS, but that procedure worked for me with
solaris 10 and failed for solaris 9. i waited for the vendor
patches.

rp
___
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml


Re: [clamav-users] FW: APPLE-SA-2011-03-21-1 Mac OS X v10.6.7 and Security Update 2011-001

2011-03-29 Thread Russ Tyndall

On Mar 29, 2011, at 1:38 PM, TR Shaw wrote:

 The problem is that the make for dynamic libraries doesn't work out of the 
 box so even if you compile the static version clam will link with the old 
 dynamic lib.

Can I tell clam where to get the bzip2 stuff? I know I am not using the right 
terminology, but will this work?

1) Compile bzip2 1.0.6 from source on a machine with the right tools and 
install it in /opt/local/lib
2) Compile clamd from source on the same machine with this flag:

export LDFLAGS=-O3 -march=i686 -L/opt/local/lib

(Is the flag above telling clamd where to get bzip2 on the machine where clamd 
is running?)

3) Copy the /opt/local/lib directory containing bzip2 to each client computer
4) Install and set up the just-compiled clamd to each client computer

Since I am leaving the OS-provided [and buggy] version 1.0.5 in place, won't 
the OS be ok?

Thanks in advance for any guidance.

-
Russ Tyndall
Wake Forest, NC



___
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml


[clamav-users] ClamXav

2011-03-29 Thread Al Varnell
Why is Mac OS X's ClamXav no longer listed on the Third Party Packages page?

Sent from Janet's iPad

-Al-
-- 
Al Varnell


___
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml