Greetings I was informed on another list about this... im not a serious programming or exploit creation expert yet this appears to me to be fairly serious..... For those of you that have not heard about it, there has been a www.clamav.net update to 88.4 I roll my own rpms so I don't wait for upstream on this one... and for all I know they have dealt with it already... Anyways, FYI Thanks and kind regards, - rh -- Robert - Abba Communications Computer & Internet Services (509) 624-7159 - www.abbacomm.net
Email Lists wrote:> Greetings > > I was informed on another list about this... im not a serious programming or > exploit creation expert yet this appears to me to be fairly serious..... > > For those of you that have not heard about it, there has been a > www.clamav.net update to 88.4 > > I roll my own rpms so I don't wait for upstream on this one... and for all I > know they have dealt with it already...rpmforge has updated packages already, but they're version 0.88.3-2, not 0.88.4, fwiw. See <http://wiki.centos.org/Repositories> on how to add rpmforge. Regards, Ralph -- Ralph Angenendt......ra at br-online.de | .."Text processing has made it possible Bayerischer Rundfunk...80300 M?nchen | ....to right-justify any idea, even one Programmbereich.Bayern 3, Jugend und | .which cannot be justified on any other Multimedia.........Tl:089.5900.16023 | ..........grounds." -- J. Finnegan, USC -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 189 bytes Desc: not available URL: <http://lists.centos.org/pipermail/centos/attachments/20060808/10b2c30f/attachment-0002.sig>
On Tue, 8 Aug 2006, Ralph Angenendt wrote:> Email Lists wrote: > > Greetings > > > > I was informed on another list about this... im not a serious programming or > > exploit creation expert yet this appears to me to be fairly serious..... > > > > For those of you that have not heard about it, there has been a > > www.clamav.net update to 88.4 > > > > I roll my own rpms so I don't wait for upstream on this one... and for all I > > know they have dealt with it already... > > rpmforge has updated packages already, but they're version 0.88.3-2, not > 0.88.4, fwiw.The patch was released before the 0.88.4 release. So I had to bring out a patched 0.88.3. Late last night they released 0.88.4 and I build it. And this morning uploaded it. The 0.88.3-2 and the 0.88.4 are identical. The clamav people anticipated to release 0.89 with the patch included but unfortunately the problem was disclosed on secunia yesterday. So they released the patch in a rush. There is a closed mailinglist for clamav packagers where they announce new releases and security patches before they're made public. The downside is that people in between 0.88.3-2 and 0.88.4 eventually had to download the same data twice. The upside is that the security-fix was released sooner. Kind regards, -- dag wieers, dag at wieers.com, http://dag.wieers.com/ -- [all I want is a warm bed and a kind word and unlimited power]