Mailing List Archive

Re: [ATrpms-devel] clamav has security update
On 08/21/2012 06:40 PM, Chris Schanzle wrote:
> On 06/15/2012 07:03 AM, Kim Bisgaard wrote:
>> Hi,
>>
>> Clamav has had a security update to 0.97.5
>>
>> The reason for this versions tarball being smaller seems to be that the virus db files are not included any more which seems reasonable. I
>> have thus updated the version in the spec and removed these 2 lines:
>> #%attr(0644,clamav,clamav) %verify(not mtime size md5) /var/lib/clamav/main.cvd
>> #%attr(0644,clamav,clamav) %verify(not mtime size md5) /var/lib/clamav/daily.cvd
>>
>> Hope you will find time for building soon.
>>
>> Regards,
>> Kim
>
>
> Would really appreciate clamav being updated...atrpms el5/6 seems to be a couple releases back at 0.97.3-61
>
> It would also be nice to have an option to not start clamd in the init script, but that's much lower priority.
>
> Thanks!

[crickets]
At this point, it would be wise to remove the insecure clamav.

That would also stop the atrpms version from trying to 'downgrade' the current EPEL one, presumably due to EPOCH in the atrpms one.


_______________________________________________
atrpms-users mailing list
atrpms-users@atrpms.net
http://lists.atrpms.net/mailman/listinfo/atrpms-users