dansguardian updated packages may break installs

Bug #199385 reported by KarlGoetz
8
Affects Status Importance Assigned to Milestone
dansguardian (Ubuntu)
Invalid
Medium
Unassigned

Bug Description

After updating an Ubuntu 6.06.1 releast to 6.06.2 (via a clean install+updates), dansguardian failed to restart properly.
It transpired that the /etc/dansguardian/dansguardianf1.conf file had extra entries, that either had not been there previously, or were now required, not optional.

This is the error that was produced:
Mar 7 16:50:13 gatekeeper dansguardian: Error reading file:
Mar 7 16:50:13 gatekeeper dansguardian:
Mar 7 16:50:13 gatekeeper dansguardian: Error reading file:
Mar 7 16:50:13 gatekeeper dansguardian:
Mar 7 16:50:13 gatekeeper dansguardian: Error opening exceptionvirusmimetypelist
Mar 7 16:50:13 gatekeeper dansguardian: Error opening filter list:
Mar 7 16:50:13 gatekeeper dansguardian: /etc/dansguardian/dansguardianf1.conf
Mar 7 16:50:13 gatekeeper dansguardian: Error reading filter group conf file(s).
Mar 7 16:50:13 gatekeeper dansguardian: Error parsing the dansguardian.conf file or other DansGuardian configuration files

This could well be a regression (Why was the antivirus plugin version allowed to change? isnt that against policy?), so i consider it worth noting.

Package information:

apt-cache policy dansguardian
dansguardian:
  Installed: 2.8.0.6-antivirus-6.4.4.1-4build1~dapper1
  Candidate: 2.8.0.6-antivirus-6.4.4.1-4build1~dapper1
  Version table:
 *** 2.8.0.6-antivirus-6.4.4.1-4build1~dapper1 0
        500 http://mirror.internode.on.net dapper-updates/universe Packages
        100 /var/lib/dpkg/status
     2.8.0.6-antivirus-6.3.8-1-1 0
        500 http://mirror.internode.on.net dapper/universe Packages

Revision history for this message
Scott Kitterman (kitterman) wrote : Re: [Bug 199385] [NEW] dansguardian updated packages may break installs

>This could well be a regression (Why was the antivirus plugin version
>allowed to change? isnt that against policy?), so i consider it worth
>noting.

It's because the old version of clamav that it uses had serious security issues and wasn't
maintainable. The updated provided fixes for (IIRC) 19 CVE bugs.

Revision history for this message
KarlGoetz (kgoetz) wrote : Re: [Bug 199385] [NEW] dansguardian updated packages may break installs

On Sat, 2008-03-08 at 02:14 +0000, Scott Kitterman wrote:
> >This could well be a regression (Why was the antivirus plugin version
> >allowed to change? isnt that against policy?), so i consider it worth
> >noting.
>
> It's because the old version of clamav that it uses had serious security issues and wasn't
> maintainable. The updated provided fixes for (IIRC) 19 CVE bugs.

fairly impressive number (i had been wondering how clamav updates would
be handled).

incase its relevent, here is the config i had to (re?) introduce to get
dans working again (which is the AV section):

# OPTION: virusscan
# If on, content will be scanned using virus engine setup in
dansguardian.conf.
# More options are available in dansguardian.conf.
virusscan = on

# OPTION: exceptionvirusextensionlist
# The following file allow you to define file extensions
# that should not be virus scanned.
exceptionvirusextensionlist =
'/etc/dansguardian/exceptionvirusextensionlist'
# OPTION: exceptionvirusmimetypelist
# The following file allow you to define mime types
# that should not be virus scanned.
exceptionvirusmimetypelist =
'/etc/dansguardian/exceptionvirusmimetypelist'

# OPTION: exceptionvirussitelist
# File location of definition of sites not be virus scanned.
exceptionvirussitelist = '/etc/dansguardian/exceptionvirussitelist'

# OPTION: exceptionvirusurllist
# File location of definition of URLs not be virus scanned.
exceptionvirusurllist = '/etc/dansguardian/exceptionvirusurllist'

# OPTION: dlmgrextensionlist
# File location of file extensions to be handled by embedded download
manager.
dlmgrextensionlist = '/etc/dansguardian/dlmgrextensionlist'

Two of these lines were already there, but i dont remember which.
kk

Revision history for this message
Thomas Hotz (thotz-deactivatedaccount) wrote :

Is this still an issue for you? Which Ubuntu version do you use? Thank you for telling us!

Revision history for this message
KarlGoetz (kgoetz) wrote :

hi,
I don't use ubuntu at the moment so I can't tell you if the problem still exists.
thanks,
kk

Changed in dansguardian (Ubuntu):
status: New → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.