Debian Bug report logs - #550296
ClamAV 0.94.x will be remotely disabled on 1th April 2010

version graph

Package: clamav; Maintainer for clamav is ClamAV Team <pkg-clamav-devel@lists.alioth.debian.org>; Source for clamav is src:clamav (PTS, buildd, popcon).

Reported by: Dominic Hargreaves <dom@earth.li>

Date: Thu, 8 Oct 2009 22:09:05 UTC

Severity: normal

Tags: lenny, security

Merged with 578037

Found in version clamav/0.94.dfsg.2-1lenny2

Done: Michael Tautschnig <mt@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, ClamAV Team <pkg-clamav-devel@lists.alioth.debian.org>:
Bug#550296; Package clamav. (Thu, 08 Oct 2009 22:09:08 GMT) (full text, mbox, link).


Acknowledgement sent to Dominic Hargreaves <dom@earth.li>:
New Bug report received and forwarded. Copy sent to ClamAV Team <pkg-clamav-devel@lists.alioth.debian.org>. (Thu, 08 Oct 2009 22:09:08 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Dominic Hargreaves <dom@earth.li>
To: submit@bugs.debian.org
Subject: ClamAV 0.94.x will be remotely disabled on 1th April 2010
Date: Thu, 8 Oct 2009 23:06:21 +0100
Package: clamav
Version: 0.94.dfsg.2-1lenny2
Severity: important

Perhaps the version from volatile should be promoted to lenny proper
before this date...

etch is also affected but I assume it will be out of support by then.

----- Forwarded message from Luca Gibelli <luca@clamav.net> -----

X-Spam-Status: No, score=-2.7 required=5.0 tests=AWL,BAYES_00,
	RCVD_IN_DNSWL_LOW,SPF_FAIL autolearn=ham version=3.2.5
Date: Tue, 6 Oct 2009 16:36:01 +0200
From: Luca Gibelli <luca@clamav.net>
To: clamav-announce@lists.clamav.net
User-Agent: Mutt/1.5.18 (2008-05-17)
Subject: [Clamav-announce] End of Life Announcement: ClamAV 0.94.x
Reply-To: noreply@clamav.net
X-Urchin-Spam-Score-Int: -26
X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.1.7


Dear ClamAV users,

all ClamAV releases older than 0.95 are affected by a bug in freshclam
which prevents incremental updates from working with signatures longer
than 980 bytes.

You can find more details on this issue on our bugzilla:
https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1395

This bug affects our ability to distribute complex signatures (e.g.
logical signatures) with incremental updates.

So far we haven't released any signatures which exceed this limit.
Before we do we want as many users as possible to upgrade to the latest
version of ClamAV.

Starting from 15 April 2010 our CVD will contain a special signature
which disables all clamd installations older than 0.95 - that is to say 
older than 1 year.
This move is needed to push more people to upgrade to 0.95 .
We would like to keep on supporting all old versions of our engine, but
unfortunately this is no longer possible without causing a disservice to
people running a recent release of ClamAV.
The traffic generated by a full CVD download, as opposed to an
incremental update, cannot be sustained by our mirrors.

We plan to start releasing signatures which exceed the 980 bytes limit
on May 2010.

We recommend that you always run the latest version of ClamAV to get
optimal protection, reliability and performance.

This message will be sent every two months to remind you to upgrade all
of your ClamAV installations in time.


Thanks for your cooperation,


Best regards


-- 
Luca Gibelli (luca _at_ clamav.net)       ClamAV, a GPL anti-virus toolkit
[Tel] +39 0187 1851862 [Fax] +39 0187 1852252 [IM] nervous/jabber.linux.it
PGP key id 5EFC5582 @ any key-server || http://www.clamav.net/gpg/luca.gpg
_______________________________________________
http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-announce

----- End forwarded message -----

-- 
Dominic Hargreaves | http://www.larted.org.uk/~dom/
PGP key 5178E2A5 from the.earth.li (keyserver,web,email)




Information forwarded to debian-bugs-dist@lists.debian.org, ClamAV Team <pkg-clamav-devel@lists.alioth.debian.org>:
Bug#550296; Package clamav. (Fri, 09 Apr 2010 12:48:03 GMT) (full text, mbox, link).


Acknowledgement sent to Török Edwin <edwintorok@gmail.com>:
Extra info received and forwarded to list. Copy sent to ClamAV Team <pkg-clamav-devel@lists.alioth.debian.org>. (Fri, 09 Apr 2010 12:48:03 GMT) (full text, mbox, link).


Message #10 received at 550296@bugs.debian.org (full text, mbox, reply):

From: Török Edwin <edwintorok@gmail.com>
To: Debian Bug Control <control@bugs.debian.org>
Cc: 550296@bugs.debian.org, 577013@bugs.debian.org
Subject: raise severity
Date: Fri, 09 Apr 2010 15:43:09 +0300
severity 577013 serious
severity 550296 grave
thanks

I meant to set severity on 550296




Severity set to 'grave' from 'important' Request was from Török Edwin <edwintorok@gmail.com> to control@bugs.debian.org. (Fri, 09 Apr 2010 12:48:10 GMT) (full text, mbox, link).


Information forwarded to debian-bugs-dist@lists.debian.org, ClamAV Team <pkg-clamav-devel@lists.alioth.debian.org>:
Bug#550296; Package clamav. (Fri, 16 Apr 2010 10:42:03 GMT) (full text, mbox, link).


Acknowledgement sent to Dylan Smith <dyls@alioth.net>:
Extra info received and forwarded to list. Copy sent to ClamAV Team <pkg-clamav-devel@lists.alioth.debian.org>. (Fri, 16 Apr 2010 10:42:04 GMT) (full text, mbox, link).


Message #17 received at 550296@bugs.debian.org (full text, mbox, reply):

From: Dylan Smith <dyls@alioth.net>
To: Debian Bug Tracking System <550296@bugs.debian.org>
Subject: clamav: ClamAV is now disabled
Date: Fri, 16 Apr 2010 11:34:13 +0100
Package: clamav
Version: 0.94.dfsg.2-1lenny2
Followup-For: Bug #550296


ClamAV no longer functions at all in Debian, and mail servers that 
depend on passing messages via ClamAV are also disabled. The version of 
ClamAV in the distribution has been disabled by the clamav authors.

-- Package-specific info:
--- configuration ---
/etc/clamav/clamd.conf: clamd directives
------------------------------
LogFile = "/var/log/clamav/clamav.log"
LogFileUnlock = no
LogFileMaxSize = 0
LogTime = yes
LogClean = no
LogVerbose = no
LogSyslog = no
LogFacility = "LOG_LOCAL6"
PidFile = "/var/run/clamav/clamd.pid"
TemporaryDirectory not set
ScanPE = yes
ScanELF = yes
DetectBrokenExecutables = no
ScanMail = yes
MailFollowURLs = no
ScanPartialMessages = no
PhishingSignatures = yes
PhishingScanURLs = yes
PhishingAlwaysBlockCloak = no
PhishingAlwaysBlockSSLMismatch = no
HeuristicScanPrecedence = no
DetectPUA = no
ExcludePUA not set
IncludePUA not set
StructuredDataDetection = no
StructuredMinCreditCardCount = 3
StructuredMinSSNCount = 3
StructuredSSNFormatNormal = yes
StructuredSSNFormatStripped = no
AlgorithmicDetection = yes
ScanHTML = yes
ScanOLE2 = yes
ScanPDF = yes
ScanArchive = yes
MaxScanSize = 104857600
MaxFileSize = 26214400
MaxRecursion = 16
MaxFiles = 10000
ArchiveLimitMemoryUsage = no
ArchiveBlockEncrypted = no
DatabaseDirectory = "/var/lib/clamav"
TCPAddr not set
TCPSocket not set
LocalSocket = "/var/run/clamav/clamd.ctl"
MaxConnectionQueueLength = 15
StreamMaxLength = 10485760
StreamMinPort = 1024
StreamMaxPort = 2048
MaxThreads = 12
ReadTimeout = 180
IdleTimeout = 30
MaxDirectoryRecursion = 15
ExcludePath not set
FollowDirectorySymlinks = no
FollowFileSymlinks = no
ExitOnOOM = no
Foreground = no
Debug = no
LeaveTemporaryFiles = no
FixStaleSocket = yes
User = "clamav"
AllowSupplementaryGroups = yes
SelfCheck = 3600
VirusEvent not set
ClamukoScanOnAccess not set
ClamukoScanOnOpen not set
ClamukoScanOnClose not set
ClamukoScanOnExec not set
ClamukoIncludePath not set
ClamukoExcludePath not set
ClamukoMaxFileSize = 5242880
DevACOnly not set
DevACDepth not set
*** MailMaxRecursion is DEPRECATED ***
*** ArchiveMaxFileSize is DEPRECATED ***
*** ArchiveMaxRecursion is DEPRECATED ***
*** ArchiveMaxFiles is DEPRECATED ***
*** ArchiveMaxCompressionRatio is DEPRECATED ***
*** ArchiveBlockMax is DEPRECATED ***

/etc/clamav/freshclam.conf: freshclam directives
------------------------------
LogFileMaxSize = 0
LogTime = no
LogVerbose = no
LogSyslog = no
LogFacility = "LOG_LOCAL6"
PidFile = "/var/run/clamav/freshclam.pid"
DatabaseDirectory = "/var/lib/clamav/"
Foreground = no
Debug = no
AllowSupplementaryGroups = no
DatabaseOwner = "clamav"
Checks = 24
UpdateLogFile = "/var/log/clamav/freshclam.log"
DNSDatabaseInfo = "current.cvd.clamav.net"
DatabaseMirror = "db.local.clamav.net"
DatabaseMirror = "database.clamav.net"
MaxAttempts = 5
ScriptedUpdates = yes
CompressLocalDatabase = no
HTTPProxyServer not set
HTTPProxyPort not set
HTTPProxyUsername not set
HTTPProxyPassword not set
HTTPUserAgent not set
NotifyClamd not set
OnUpdateExecute not set
OnErrorExecute not set
OnOutdatedExecute not set
LocalIPAddress not set
ConnectTimeout = 30
ReceiveTimeout = 30
SubmitDetectionStats not set
DetectionStatsCountry not set

Engine and signature databases
------------------------------
Engine version: 0.94.2
Database directory: /var/lib/clamav/
main db: Format: .cvd, Version: 52, Build time: Mon Feb 15 14:54:51 2010
daily db: Not found

--- data dir ---
total 26696
-rw-r--r-- 1 clamav clamav  3162112 2010-04-16 04:37 daily.cld.bak
-rw-r--r-- 1 clamav clamav  1223184 2010-04-16 10:38 daily.cvd.bak
-rw-r--r-- 1 clamav clamav 22906487 2010-02-15 14:54 main.cvd
-rw-r--r-- 1 clamav clamav     1924 2010-04-16 10:38 mirrors.dat

-- System Information:
Debian Release: 5.0.4
  APT prefers stable
  APT policy: (500, 'stable')
Architecture: i386 (i686)

Kernel: Linux 2.6.26-2-686 (SMP w/1 CPU core)
Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages clamav depends on:
ii  clamav-freshclam [cl 0.94.dfsg.2-1lenny2 anti-virus utility for Unix - viru
ii  libbz2-1.0           1.0.5-1             high-quality block-sorting file co
ii  libc6                2.7-18lenny2        GNU C Library: Shared libraries
ii  libclamav5           0.94.dfsg.2-1lenny2 anti-virus utility for Unix - libr
ii  libgmp3c2            2:4.2.2+dfsg-3      Multiprecision arithmetic library
ii  zlib1g               1:1.2.3.3.dfsg-12   compression library - runtime

Versions of packages clamav recommends:
ii  clamav-base          0.94.dfsg.2-1lenny2 anti-virus utility for Unix - base

Versions of packages clamav suggests:
pn  clamav-docs                   <none>     (no description available)
pn  lha                           <none>     (no description available)
pn  unrar                         <none>     (no description available)

-- no debconf information




Information forwarded to debian-bugs-dist@lists.debian.org, ClamAV Team <pkg-clamav-devel@lists.alioth.debian.org>:
Bug#550296; Package clamav. (Fri, 16 Apr 2010 10:51:03 GMT) (full text, mbox, link).


Acknowledgement sent to Franz Georg Köhler <fgkoehler@velia.net>:
Extra info received and forwarded to list. Copy sent to ClamAV Team <pkg-clamav-devel@lists.alioth.debian.org>. (Fri, 16 Apr 2010 10:51:03 GMT) (full text, mbox, link).


Message #22 received at 550296@bugs.debian.org (full text, mbox, reply):

From: Franz Georg Köhler <fgkoehler@velia.net>
To: 550296@bugs.debian.org
Subject: clamav .04 disabled
Date: Fri, 16 Apr 2010 12:18:57 +0200
clamaav 0.94 is disabled now and therefore useless.... it should be 
updated or removed from stable distribution.




Merged 550296 578037. Request was from Michael Tautschnig <mt@debian.org> to control@bugs.debian.org. (Sat, 17 Apr 2010 21:51:03 GMT) (full text, mbox, link).


Severity set to 'serious' from 'grave' Request was from Michael Biebl <biebl@debian.org> to control@bugs.debian.org. (Wed, 05 May 2010 14:27:08 GMT) (full text, mbox, link).


Severity set to 'grave' from 'serious' Request was from Michael Biebl <biebl@debian.org> to control@bugs.debian.org. (Wed, 05 May 2010 14:33:05 GMT) (full text, mbox, link).


Severity set to 'normal' from 'grave' Request was from Stephen Gran <sgran@debian.org> to control@bugs.debian.org. (Mon, 26 Jul 2010 18:39:07 GMT) (full text, mbox, link).


Bug closed, send any further explanations to Dominic Hargreaves <dom@earth.li> Request was from Michael Tautschnig <mt@debian.org> to control@bugs.debian.org. (Thu, 10 Mar 2011 23:48:08 GMT) (full text, mbox, link).


Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Fri, 08 Apr 2011 07:48:09 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Sun Jan 14 01:00:16 2024; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.