Comment 10 for bug 217256

Revision history for this message
Scott Kitterman (kitterman) wrote : Re: [Bug 217256] Re: ClamAV Upack Processing Buffer Overflow Vulnerability

Yes. I think it's the best course. We have 0.92.1 in Hardy and all the
backports repositories. Given 0.92 to 0.92.1 caused no problems in Hardy I
think it's very low risk.

I'd like to pursue a similar course for Feisty and Gutsy, although the diff
there is rather larger. It is still much less than updating Dapper was
(the original 0.88.2 to 0.92 jump) and that went pretty smoothly.