<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Clam AntiVirus &#187; security</title>
	<atom:link href="http://www.clamav.net/lang/ru/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.clamav.net</link>
	<description>ClamAV, a GPL anti-virus toolkit for UNIX</description>
	<lastBuildDate>Mon, 09 Apr 2012 18:36:00 +0000</lastBuildDate>
	<language>ru</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>End of Life Announcement: ClamAV 0.94.x</title>
		<link>http://www.clamav.net/lang/ru/2009/10/05/eol-clamav-094</link>
		<comments>http://www.clamav.net/lang/ru/2009/10/05/eol-clamav-094#comments</comments>
		<pubDate>Mon, 05 Oct 2009 12:26:09 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.clamav.net/2009/10/05/end-of-life-announcement-clamav-094x/</guid>
		<description><![CDATA[All ClamAV releases older than 0.95 are affected by a bug in freshclam which prevents incremental updates from working with signatures longer than 980 bytes. You can find more details on this issue on our bugzilla (see bug #1395) This bug affects our ability to distribute complex signatures (e.g. logical signatures) with incremental updates. So [...]]]></description>
			<content:encoded><![CDATA[	<p>All ClamAV releases older than 0.95 are affected by a bug in freshclam which prevents incremental updates from working with signatures longer than 980 bytes.                                                                              <br />
You can find more details on this issue on our bugzilla (see <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1395">bug #1395</a>)</p>
	<p>This bug affects our ability to distribute complex signatures (e.g. logical signatures) with incremental updates.</p>
	<p>So far we haven&#8217;t released any signatures which exceed this limit.<br />
Before we do we want as many users as possible to upgrade to the latest version of ClamAV.                                                              </p>
	<p>Starting from 15 April 2010 our CVD will contain a special signature which disables all clamd installations older than 0.95 &#8211; that is to say older than 1 year.</p>
	<p>This move is needed to push more people to upgrade to 0.95 . <br />
We would like to keep on supporting all old versions of our engine, but unfortunately this is no longer possible without causing a disservice to people running a recent release of ClamAV.<br />
The traffic generated by a full CVD download, as opposed to an incremental update, cannot be sustained by our mirrors.</p>
	<p>We plan to start releasing signatures which exceed the 980 bytes limit on May 2010.</p>
	<p>We recommend that you always run the latest version of ClamAV to get optimal protection, reliability and performance.</p>
	<p>Thanks for your cooperation!</p>

 ]]></content:encoded>
			<wfw:commentRss>http://www.clamav.net/lang/ru/2009/10/05/eol-clamav-094/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ClamAV 0.94.1 released</title>
		<link>http://www.clamav.net/lang/ru/2008/11/03/clamav-0941-released</link>
		<comments>http://www.clamav.net/lang/ru/2008/11/03/clamav-0941-released#comments</comments>
		<pubDate>Mon, 03 Nov 2008 08:51:09 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[in the press]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.clamav.net/2008/11/03/clamav-0941-released/</guid>
		<description><![CDATA[There is one new feature in this release. This feature allows ClamAV users optionally to submit statistics to us about what they detect in the field. We will then use this data to determine what types of Malware/Viruses are the most detected in the field and in what geographic area they are. It closes the [...]]]></description>
			<content:encoded><![CDATA[	<p>There is one new feature in this release. This feature allows ClamAV users optionally to submit statistics to us about what they detect in the field. We will then use this data to determine what types of Malware/Viruses are the most detected in the field and in what geographic area they are.<br />

It closes the following bugs from <a href="http://bugs.clamav.net">http://bugs.clamav.net:<br />
</p>
	<p><a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=684">684</a>,<a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=777">777</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=828">828</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=832">832</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=954">954</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1046">1046</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1085">1085</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1092">1092</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1098">1098</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1135">1135</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1137">1137</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1145">1145</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1150">1150 </a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1154">1154</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1155">1155</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1157">1157</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1158">1158</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1160">1160</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1162">1162</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1165">1165</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1174">1174</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1179">1179</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1181">1181</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1184">1184</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1185">1185</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1186">1186</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1187">1187</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1189">1189</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1192">1192</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1196">1196</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1197">1197</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1199">1199</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1201">1201</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1203">1203</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1204">1204</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1205">1205</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1210">1210 </a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1211">1211</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1212">1212</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1213">1213</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1216">1216</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1217">1217</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1219">1219</a>, <a href="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1221">1221</a> <br />
<br />

For more details, please refer to <a href="http://www.clamav.net/press/0.94.1-WhatsNew.pdf">Whats New in 0.94.1</a>.</p>


 ]]></content:encoded>
			<wfw:commentRss>http://www.clamav.net/lang/ru/2008/11/03/clamav-0941-released/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security fixes in 0.88.4</title>
		<link>http://www.clamav.net/lang/ru/2006/08/07/security-fixes-in-0884</link>
		<comments>http://www.clamav.net/lang/ru/2006/08/07/security-fixes-in-0884#comments</comments>
		<pubDate>Sat, 23 Sep 2006 01:41:09 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www2.clamav.net/?p=28</guid>
		<description><![CDATA[CVE: CVE-2006-4018 Status: Critical Vulnerable: ClamAV 0.81 &#8211; 0.88.3 A heap overflow vulnerability was discovered in libclamav which could cause a denial of service or allow the execution of arbitrary code. The problem is specifically located in the PE file rebuild function used by the UPX unpacker. Relevant code from libclamav/upx.c: memcpy(dst, newbuf, foffset); *dsize [...]]]></description>
			<content:encoded><![CDATA[	<p>CVE: CVE-2006-4018 <br />
Status: Critical <br />
Vulnerable: ClamAV 0.81 &#8211; 0.88.3 </p>
	<p>A heap overflow vulnerability was discovered in libclamav which could cause a denial of service or allow the execution of arbitrary code. </p>
	<p>The problem is specifically located in the PE file rebuild function used by the UPX unpacker. </p>
	<p>Relevant code from libclamav/upx.c: </p>
<pre>
<code>
  memcpy(dst, newbuf, foffset);
  *dsize = foffset;
  free(newbuf);
  cli_dbgmsg("UPX: PE structure rebuilt from compressed file\n");
  return 1;
</code>
</pre>
	<p>Due to improper validation it is possible to overflow the above memcpy() beyond the allocated memory block. </p>
	<p>The problem has been fixed in 0.88.4. </p>


 ]]></content:encoded>
			<wfw:commentRss>http://www.clamav.net/lang/ru/2006/08/07/security-fixes-in-0884/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security fixes in 0.88.2</title>
		<link>http://www.clamav.net/lang/ru/2006/04/29/security-fixes-in-0882</link>
		<comments>http://www.clamav.net/lang/ru/2006/04/29/security-fixes-in-0882#comments</comments>
		<pubDate>Sat, 23 Sep 2006 01:39:40 +0000</pubDate>
		<dc:creator>webmaster</dc:creator>
				<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www2.clamav.net/?p=27</guid>
		<description><![CDATA[CVE: CVE-2006-1989 Status: Moderate risk Vulnerable: ClamAV 0.80 &#8211; 0.88.1 Freshclam is a command line utility responsible for downloading and installing virus signature updates. One of its features is a HTTP client performing file downloads from web servers. A security vulnerability in the protocol code was discovered independently by Ulf Harnhammar and an anonymous researcher [...]]]></description>
			<content:encoded><![CDATA[	<p>CVE: CVE-2006-1989 <br />
Status: Moderate risk <br />
Vulnerable: ClamAV 0.80 &#8211; 0.88.1 </p>
	<p>Freshclam is a command line utility responsible for downloading and installing virus signature updates. One of its features is a HTTP client performing file downloads from web servers. A security vulnerability in the protocol code was discovered independently by Ulf Harnhammar and an anonymous researcher from Germany. </p>
	<p>The problem exists due to a lack of proper check for the size of header data received from a web server: </p>
<pre><code>
int get_database(const char *dbfile, int socketfd, const char *file, const char *hostname, const char *proxy, const char *user, const char *pass) {
        char cmd [512], buffer [FILEBUFF], * ch;
[...]
   / * read all the http headers * / 
    ch = buffer;
    i = 0;
    while (1) {
        / * recv one byte at a time, until we reach \r\n\r\n * /
        if(recv(socketfd, buffer + i, 1, 0) == -1) {
[...]
</code>
</pre>
	<p>The code assumes the size of all headers returned by the web server is smaller than 8 KB. A specially prepared HTTP server could be used by an attacker to exploit freshclam clients connecting to the database mirror. The bug was classified as moderate risk. The ClamAV project uses a big number of database mirrors gathered into round robin records. In most cases the system looks up the GeoIP database to redirect users to the closest pool of mirrors. Remote exploitation (Denial of Service) can be achieved by changing one of the mirrors configurations to run a special web server returning wrong header data or by pointing freshclam to a bogus mirror i.e. by means of DNS poisoning. Remote execution of arbitrary code is not easy due to diversity of client platforms and architectures.</p>


 ]]></content:encoded>
			<wfw:commentRss>http://www.clamav.net/lang/ru/2006/04/29/security-fixes-in-0882/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

