Mailing List Archive

[clamav-users] CLAMAV 0.99.2 question about last valid definition
I am in a situation (just started working here last month) where I have an install of a few RHEL 5.5 machines that are an embedded (and on a non internet connected network) and are scheduled for replacement, the clamav on these machines
is 0.99.2 and the current definitions fail so my question is:

what would be the last definition date that would work with this clamav 0.99.2
Re: [clamav-users] CLAMAV 0.99.2 question about last valid definition [ In reply to ]
Citeren 99r c via clamav-users <clamav-users@lists.clamav.net>:

> I am in a situation (just started working here last month) where I
> have an install of a few RHEL 5.5 machines that are an embedded (and
> on a non internet connected network) and are scheduled for
> replacement, the clamav on these machines
> is 0.99.2 and the current definitions fail so my question is:
>
> what would be the last definition date that would work with this
> clamav 0.99.2

None at all. You shouldn't be running a four year old virus scanner
with known security problems:

https://www.cvedetails.com/vulnerability-list/vendor_id-8871/product_id-15657/version_id-218257/Clamav-Clamav-0.99.2.html

You can't trust whatever you throwing at the virus scanner not to
abuse any of these issues. If you really need to keep these systems
up, unplug them from the network and remove all possibilities to read
removable media (you don't need a virus scanner anymore in that case).


_______________________________________________

clamav-users mailing list
clamav-users@lists.clamav.net
https://lists.clamav.net/mailman/listinfo/clamav-users


Help us build a comprehensive ClamAV guide:
https://github.com/vrtadmin/clamav-faq

http://www.clamav.net/contact.html#ml
Re: [clamav-users] CLAMAV 0.99.2 question about last valid definition [ In reply to ]
Agreed. You need to upgrade the engine.

Sent from my ? iPad

> On Feb 26, 2020, at 10:12, Arjen de Korte via clamav-users <clamav-users@lists.clamav.net> wrote:
>
> ?Citeren 99r c via clamav-users <clamav-users@lists.clamav.net>:
>
>> I am in a situation (just started working here last month) where I have an install of a few RHEL 5.5 machines that are an embedded (and on a non internet connected network) and are scheduled for replacement, the clamav on these machines
>> is 0.99.2 and the current definitions fail so my question is:
>>
>> what would be the last definition date that would work with this clamav 0.99.2
>
> None at all. You shouldn't be running a four year old virus scanner with known security problems:
>
> https://www.cvedetails.com/vulnerability-list/vendor_id-8871/product_id-15657/version_id-218257/Clamav-Clamav-0.99.2.html
>
> You can't trust whatever you throwing at the virus scanner not to abuse any of these issues. If you really need to keep these systems up, unplug them from the network and remove all possibilities to read removable media (you don't need a virus scanner anymore in that case).
>
>
> _______________________________________________
>
> clamav-users mailing list
> clamav-users@lists.clamav.net
> https://lists.clamav.net/mailman/listinfo/clamav-users
>
>
> Help us build a comprehensive ClamAV guide:
> https://github.com/vrtadmin/clamav-faq
>
> http://www.clamav.net/contact.html#ml