From owner-freebsd-ports@FreeBSD.ORG Wed Feb 18 17:11:32 2004 Return-Path: Delivered-To: freebsd-ports@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id E258916A4CE; Wed, 18 Feb 2004 17:11:32 -0800 (PST) Received: from postman.arcor.de (postman2.arcor-online.net [151.189.0.152]) by mx1.FreeBSD.org (Postfix) with ESMTP id 5E91943D31; Wed, 18 Feb 2004 17:11:32 -0800 (PST) (envelope-from eikemeier@fillmore-labs.com) Received: from fillmore.dyndns.org (port-212-202-184-227.reverse.qdsl-home.de [212.202.184.227]) (authenticated bits=0)i1J1BUf5023432 (version=TLSv1/SSLv3 cipher=EDH-RSA-DES-CBC3-SHA bits=168 verify=NO); Thu, 19 Feb 2004 02:11:30 +0100 (MET) Received: from [172.16.0.2] (helo=fillmore-labs.com) by fillmore.dyndns.org with esmtp (Exim 4.30; FreeBSD) id 1Atciu-000NJV-79; Thu, 19 Feb 2004 02:11:28 +0100 Message-ID: <40340D3F.8060805@fillmore-labs.com> Date: Thu, 19 Feb 2004 02:11:27 +0100 From: Oliver Eikemeier Organization: Fillmore Labs GmbH - http://www.fillmore-labs.com/ MIME-Version: 1.0 To: "Jacques A. Vidrine" References: <40337619.1050504@veldy.net> <20040218215950.GD47727@madman.celabo.org> In-Reply-To: <20040218215950.GD47727@madman.celabo.org> Content-Type: text/plain; charset=us-ascii; format=flowed Content-Transfer-Encoding: 7bit User-Agent: KMail/1.5.9 cc: "Thomas T. Veldhouse" cc: freebsd-security@FreeBSD.org cc: freebsd-ports@FreeBSD.org Subject: Re: [Fwd: [gentoo-announce] [ GLSA 200402-07 ] Clamav 0.65 DoS vulnerability] X-BeenThere: freebsd-ports@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Porting software to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 19 Feb 2004 01:11:33 -0000 Jacques A. Vidrine wrote: > On Wed, Feb 18, 2004 at 08:26:33AM -0600, Thomas T. Veldhouse wrote: > >>Attached is a security alert from Gentoo pertaining to clam antivirus. >>It seems that as of this morning, FreeBSD's ports still contain the >>affected version. > > Oliver (the discoverer of the vulnerability) is a FreeBSD developer and > fixed the port some time ago. > > See also > . Btw, it is almost unbearable smart that they include the sequence that triggers the bug in their mail, assuring that users that *have* the vulnerable clamd installed never see the advisory. It *had* a reason that I prefixed the lines with 'X'. Congratulations. -Oliver