[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: ClamAV And unrar - Bug #465207



This one time, at band camp, Johann Spies said:
> On Wed, Feb 27, 2008 at 01:06:33PM +0000, Stephen Gran wrote:
> > This one time, at band camp, Johann Spies said:
> > > On Wed, Feb 27, 2008 at 11:54:19AM +0000, Stephen Gran wrote:
> > > > report to say:
> > > > 
> > > > "There is a hard coded path in clamscan that calls internal unpackers
> > > > for zip and rar before trying the specified external unpackers.  This
> > > > breaks rar and some zip scanning for no clearly good reason.  I am
> > > > talking with upstream about it."
> > > > 
> > > 
> > > Would that be the cause of a lot of entries like this in our exim logs:
> > > 
> > > 2008-02-27 06:28:19 1JUDru-0007jl-Va spam acl condition: error reading
> > > from spamd socket: Connection timed out
> > > ?
> > 
> > It seems unlikely to me that a failure to unpack something in clamav
> > would lead to a timeout in spamd.  They each do their own mime
> > handling.
> 
> That is a very polite answer to a stupid mistake I made.  I pasted the
> wrong line into the email. Here is the intended log-entry which I
> think might be related to this bug - or not?
> 
> 2008-02-28 09:07:30 1JUcqv-0001DE-KH malware acl condition: clamd:
> ClamAV returned
> /var/spool/exim4/scan/1JUcqv-0001DE-KH/1JUcqv-0001DE-KH-00002.zip: Zip
> module failure ERROR

Ah, that one is clamav :)

This is likely to be a format of zip file that clamav doesn't yet
understand how to unpack.  There are, unfortunately, lots and lots of
formats for compression out there, and while more decompressors are
being added to clamav all the time, we don't yet have all of them
covered.  If you have the zip file that caused the failure, I would
appreciate it if you could submit it to upstream's bugzilla at
http://bugs.clamav.net .  If you don't feel like managing a new bug
login, you can of course submit it as a Debian bug, and I'll forward it
upstream.

This has nothing to do with the rar issues.

Cheers,
-- 
 -----------------------------------------------------------------
|   ,''`.                                            Stephen Gran |
|  : :' :                                        sgran@debian.org |
|  `. `'                        Debian user, admin, and developer |
|    `-                                     http://www.debian.org |
 -----------------------------------------------------------------

Attachment: signature.asc
Description: Digital signature


Reply to: