Comment 1 for bug 1673284

Revision history for this message
Eli Schwartz (eschwartz) wrote : Re: [Bug 1673284] [NEW] ClamAV reporting calibre as being infected with CVE 2017 0141

Looks like a reserved ID, though, nothing to see here...
https://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0141

Anyway, that file is the bundled rapydscript-to-javascript transpiler
used to build the experimental new server. In the unlikely event that
there is an *actual* vulnerability there (and note that calibre is
open-source and certainly does not deliberately ship vulnerabilities) it
will never be accessed regardless -- unless you use calibre's python
interpreter to rebuild the presumably-modified *.pyj files from the
source code checkout described in the manual under "Setting up a calibre
development environment".