Dapper clamav has multiple security issues that require upgrade to new version to fix

Bug #190187 reported by Scott Kitterman
254
Affects Status Importance Assigned to Milestone
clamav (Ubuntu)
Fix Released
Undecided
Unassigned
Dapper
Fix Released
High
Unassigned

Bug Description

Binary package hint: clamav

The current clamav in Dapper is ancient and unmaintainable given upstream's maintenance philosophy (just upgrade to the current version). The current (0.92) clamav and all it's rdepends have been tested in a PPA and uploaded to backports for several weeks with no bugs filed.

https://wiki.ubuntu.com/MOTU/Clamav

https://launchpad.net/~ubuntu-clamav/+archive

Note: The PPA and the test page cover all releases, so some packages are listed which do not apply to Dapper.

The following packages should be copied from dapper-backports to dapper-updates/proposed depending of the PPA testing is considered adequate (my recommendation is straight to updates - needing to get all the new packages re-tested would delay this transition for some time).

avscan - 1.3.1-openssl-4~dapper1
clamav - 0.92~dfsg-2~dapper1
clamcour - 0.2.2-1.2build1~dapper1
clamtk - 3.06-1~dapper1
dansguardian - 2.8.0.6-antivirus-6.4.4.1-4build1~dapper1
endeavour - 2.7.5-1ubuntu1~dapper1
etpan-ng - 0.7.1-4~dapper1
havp - 0.86-1build1~dapper1
klamav - 0.41.1-0ubuntu2~dapper1
libetpan - 0.48-2~dapper1
php-clamavlib - 0.12a-4~dapper1
python-clamav - 0.4.0-1build1~dapper1
sylpheed-claws - 1.0.5-5.1ubuntu0.1~dapper1
sylpheed-claws-gtk2 - 2.6.0-1.1ubuntu1~dapper1

Changed in clamav:
status: New → Fix Released
importance: Undecided → High
milestone: none → dapper-updates
status: New → Triaged
Revision history for this message
Martin Pitt (pitti) wrote :

Copied to -updates, as discussed on IRC. The verification was performed very thoroughly in -backports.

Changed in clamav:
status: Triaged → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.