Re: [Full-Disclosure] [ GLSA 200501-46 ] ClamAV: Multiple issues

From: Trog (trog_at_uncon.org)
Date: 02/01/05

  • Next message: Marc Deslauriers: "[Full-Disclosure] [FLSA-2005:2187] Updated freeradius packages fix security flaws"
    To: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
    Date: Tue, 01 Feb 2005 09:09:18 +0000
    
    
    

    On Mon, 2005-01-31 at 20:41 +0100, Sune Kloppenborg Jeppesen wrote:

    >
    > By sending a base64 encoded image file in a URL an attacker could evade
    > virus scanning.

    It's somewhat harsh to single out ClamAV for this issue. AFAICT, the
    only two virus scanners that do currently protect against this are
    ClamAV and AntiVir.

    According to current testing, all the others, including:

    AVG
    Avast
    BitDefender
    DrWeb
    eTrust-Iris
    eTrust-Vet
    F-Prot
    F-Secure
    Kaspersky
    mks_vir
    NOD32
    Norman Virus Control
    Panda8
    Sophos
    Sybari
    Symantec

    do not offer protection against this issue. If anyone sees any errors in
    the list above, please let me know

    -trog

    
    



  • Next message: Marc Deslauriers: "[Full-Disclosure] [FLSA-2005:2187] Updated freeradius packages fix security flaws"

    Relevant Pages

    • Re: How can I turn off Norton AV?
      ... >protect is OFF and I can't enable it. ... Email scanning is enabled and I ... What is the date of your virus definitions for NAV2004? ... be separate entries for Live Update and for Live Reg in the Add/Remove ...
      (microsoft.public.windowsxp.general)
    • Re: Virus check of incoming e-mail
      ... fear that their computer is infected with a virus. ... Even the most well-known anti-virus programs have ... scan is necessary to protect your computer. ... from the message and saves it to the Temporary Internet Files folder on your ...
      (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
    • Re: HELP! KLEZ & PE_ELKERN.A Virus
      ... > I have Windows XP Microsoft Outlook Express. ... > recently contaminated KLEZ & PE_ELKERN viruses which I ... The problem, I think, lies with the virus ... Almost any virus protection software would protect you from something ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Cerner hopefully is using Zotob to show why hospitals should run VMS! VMS! VMS!
      ... > And you reminded me that Spybot anti-spyware utility has the capability ... > to write protect the host/lmhost file on a windows box and protct ... Typically one of the first things a virus will do is try to ... To add insult to injury Symantec reported that infection as ...
      (comp.os.vms)
    • Re: MICROSOFT XP OS UNBREAKABLE WITH...
      ... > How about I write you your own virus. ... >>> feel about viruses and trojans. ... No card, no matter ... >> off your HD if you refuse to protect yourself. ...
      (microsoft.public.windowsxp.hardware)

  • Quantcast