Please backport clamav 0.88.7-1ubuntu1 to edgy from feisty

Bug #83065 reported by Steven
6
Affects Status Importance Assigned to Milestone
Edgy Backports
Fix Released
Wishlist
Colin Watson

Bug Description

Please backport ClamAV 0.88.7 to edgy. This release includes security updates. See the comment below for changelog.

Revision history for this message
Luca Falavigna (dktrkranz) wrote :

ClamAV 0.88.7 is not in Ubuntu repository yet (Debian ships 0.90~rc3).

Revision history for this message
Steven (stebalien) wrote :

As far as I can see ClamAV 0.88.7 IS in the Ubuntu repository.

Quoted From http://packages.ubuntu.com/cgi-bin/search_packages.pl?searchon=names&keywords=clamav&version=feisty&subword=1&release=all
"
Package clamav

    * feisty (utils): antivirus scanner for Unix [universe]
      0.88.7-1ubuntu1: amd64 i386 powerpc
"

Revision history for this message
Luca Falavigna (dktrkranz) wrote :

Oops, I looked at Edgy instead of Feisty :)
Anyway, it works for me: ** Success!.

Changed in edgy-backports:
status: Unconfirmed → Confirmed
Revision history for this message
John Dong (jdong) wrote :

0.90 cannot be backported because its API has changed, requiring everything clamav related to be rebuilt, and nulling the binary compatibility of edgy-backports with a regular edgy system.

The issue of clamav is a pending one being discussed on the -motu mailing list.

Changed in edgy-backports:
status: Confirmed → Rejected
Revision history for this message
Scott Kitterman (kitterman) wrote :
Download full text (3.5 KiB)

As an interim measure we want to go ahead and backport 0.88.7 while we work out the API change issues with 0.9x. Debian/changelog since the last Edgy version (in edgy-security):

clamav (0.88.7-1ubuntu1) feisty; urgency=low

  * Merge from debian unstable, remaining changes:
    - debian/clamav-base.init-stub, debian/clamav-daemon.init,
      debian/rules: init script stub for common setup functions.

 -- Kees Cook <email address hidden> Tue, 12 Dec 2006 16:04:26 -0800

clamav (0.88.7-1) unstable; urgency=medium

  * New upstream version
    [ CVE-2006-6406 ] MIME encoding scan bypass (closes: #401873)
    [ CVE unavailable ] Nested multipart recursion DoS (closes: #401874)

 -- Stephen Gran <email address hidden> Tue, 12 Dec 2006 00:38:02 +0000

clamav (0.88.6-1ubuntu1) feisty; urgency=low

  * Merge from debian unstable.
  * Remaining Ubuntu changes:
    - debian/clamav-base.init-stub, debian/clamav-daemon.init,
      debian/rules: init script stub for common setup functions.

 -- Kees Cook <email address hidden> Tue, 28 Nov 2006 21:22:48 -0800

clamav (0.88.6-1) unstable; urgency=low

  * New upstream version
    - incorporates freshclam non-block patch, thus dropping it from patches/

 -- Stephen Gran <email address hidden> Mon, 6 Nov 2006 11:19:38 +0000

clamav (0.88.5-3) unstable; urgency=low

  * Fix broken configure.in patch. Never mattered on systems where sendmail
    wasn't installed, but would make the build system fail to pick up local
    versions of sendmail on custom arrangements

 -- Stephen Gran <email address hidden> Mon, 23 Oct 2006 23:18:59 +0100

clamav (0.88.5-2) unstable; urgency=high

  * Fix FTBFS with nullmailer (closes: #393672)
  * Urgency high because this was keeping security fixes out of testing
  * Noted here since they were unavailable at previous upload time:
    - IDEF1597 is CVE-2006-4182 (libclamav/rebuildpe.c)
    - IDEF1736 is CVE-2006-5295 (libclamav/chmunpack.c)

 -- Stephen Gran <email address hidden> Thu, 19 Oct 2006 12:30:07 +0100

clamav (0.88.5-1) unstable; urgency=medium

  * New upstream version
    - libclamav/rebuildpe.c: fix possible heap overflow [IDEF1597]
    - libclamav/chmunpack.c: fix possible crash [IDEF1736]
    - urgency medium for this reason

 -- Stephen Gran <email address hidden> Mon, 16 Oct 2006 01:40:57 +0100

clamav (0.88.4-4) unstable; urgency=low

  * Versioned build-dep on dpkg-dev so I can use ${binary:Version}
  * Actually remove Magnus this time
  * Add Recommends clamav-base to clamav (closes: #391038)
  * Fix parse problem is slurp_config() (closes: #384046)

 -- Stephen Gran <email address hidden> Sun, 8 Oct 2006 13:39:15 +0100

clamav (0.88.4-3) unstable; urgency=low

  * Move logrotate handling to clamav-daemon.postrm (closes: #384011)
  * Apply upstream freshclam timeout patch (closes: #334911, #382353)
  * Actually install changelogs, symlink other docs.
  * Make binary packages binNMU'able
  * lsb init comments added to init scripts
  * Remove Magnus from Uploaders field, as it looks like he's really not
    coming back to it. Thanks for all your work, Magnus!
  * Add shlibsdeps to clamav-dbg

 -- Stephen Gran <email address hidden> Mon, 2 Oct 2006 19:47:06 +0100

clamav (0.88.4-2) un...

Read more...

Changed in edgy-backports:
status: Invalid → Incomplete
description: updated
Revision history for this message
Leonel Nunez (leonelnunez) wrote :

Builded https://launchpad.net/ubuntu/+source/clamav/0.88.7-1ubuntu1 on Edgy.
installed and tested with clamsmtp and clamassassin
all worked fine

Changed in edgy-backports:
status: Incomplete → In Progress
importance: Undecided → High
Revision history for this message
Martin Pitt (pitti) wrote :

This does not make sense. Feisty has 0.90.2-0ubuntu1, 0.88.7 is not in the archive at all.

Changed in edgy-backports:
status: In Progress → Incomplete
Changed in edgy-backports:
importance: High → Wishlist
status: Incomplete → In Progress
Revision history for this message
Colin Watson (cjwatson) wrote :

Resurrected and backported 0.88.7-1ubuntu1 to Edgy. Don't ask how and I won't have to tell you.

Changed in edgy-backports:
assignee: nobody → kamion
status: In Progress → Fix Released
Revision history for this message
Scott Kitterman (kitterman) wrote :
Download full text (4.1 KiB)

Accepted:
 OK: clamav_0.88.7.orig.tar.gz
 OK: clamav_0.88.7-1ubuntu1~edgy1.diff.gz
 OK: clamav_0.88.7-1ubuntu1~edgy1.dsc
     -> Component: universe Section: utils

Format: 1.7
Date: Mon, 16 Jul 2007 14:29:13 +0100
Source: clamav
Binary: clamav libclamav-dev clamav-dbg clamav-milter clamav-base clamav-freshclam clamav-testfiles clamav-daemon libclamav1 clamav-docs
Architecture: source
Version: 0.88.7-1ubuntu1~edgy1
Distribution: edgy-backports
Urgency: high
Maintainer: Stephen Gran <email address hidden>
Changed-By: Scott Kitterman <email address hidden>
Description:
 clamav - antivirus scanner for Unix
 clamav-base - base package for clamav, an anti-virus utility for Unix
 clamav-daemon - antivirus scanner daemon
 clamav-dbg - debug symbols for clamav
 clamav-docs - documentation package for clamav, an anti-virus utility for Unix
 clamav-freshclam - downloads clamav virus databases from the Internet
 clamav-milter - antivirus scanner for sendmail
 clamav-testfiles - use these files to test that your Antivirus program works
 libclamav-dev - clam Antivirus library development files
 libclamav1 - virus scanner library
Closes: 334911 382092 382353 384011 384046 391038 393672 401873 401874
Changes:
 clamav (0.88.7-1ubuntu1~edgy1) edgy-backports; urgency=low
 .
   * Automated backport upload; no source changes.
 .
 clamav (0.88.7-1ubuntu1) feisty; urgency=low
 .
   * Merge from debian unstable, remaining changes:
     - debian/clamav-base.init-stub, debian/clamav-daemon.init,
       debian/rules: init script stub for common setup functions.
 .
 clamav (0.88.7-1) unstable; urgency=medium
 .
   * New upstream version
     [ CVE-2006-6406 ] MIME encoding scan bypass (closes: #401873)
     [ CVE unavailable ] Nested multipart recursion DoS (closes: #401874)
 .
 clamav (0.88.6-1ubuntu1) feisty; urgency=low
 .
   * Merge from debian unstable.
   * Remaining Ubuntu changes:
     - debian/clamav-base.init-stub, debian/clamav-daemon.init,
       debian/rules: init script stub for common setup functions.
 .
 clamav (0.88.6-1) unstable; urgency=low
 .
   * New upstream version
     - incorporates freshclam non-block patch, thus dropping it from patches/
 .
 clamav (0.88.5-3) unstable; urgency=low
 .
   * Fix broken configure.in patch. Never mattered on systems where sendmail
     wasn't installed, but would make the build system fail to pick up local
     versions of sendmail on custom arrangements
 .
 clamav (0.88.5-2) unstable; urgency=high
 .
   * Fix FTBFS with nullmailer (closes: #393672)
   * Urgency high because this was keeping security fixes out of testing
   * Noted here since they were unavailable at previous upload time:
     - IDEF1597 is CVE-2006-4182 (libclamav/rebuildpe.c)
     - IDEF1736 is CVE-2006-5295 (libclamav/chmunpack.c)
 .
 clamav (0.88.5-1) unstable; urgency=medium
 .
   * New upstream version
     - libclamav/rebuildpe.c: fix possible heap overflow [IDEF1597]
     - libclamav/chmunpack.c: fix possible crash [IDEF1736]
     - urgency medium for this reason
 .
 clamav (0.88.4-4) unstable; urgency=low
 .
   * Versioned build-dep on dpkg-dev so I can use...

Read more...

Changed in edgy-backports:
assignee: kamion → nobody
Revision history for this message
Scott Kitterman (kitterman) wrote :

Re-assigning since I stepped on Colin's status change.

Changed in edgy-backports:
assignee: nobody → kamion
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.