-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sat, 02 May 2015 23:27:36 +0200 Source: clamav Binary: clamav-base clamav-docs clamav-dbg clamav libclamav-dev libclamav6 clamav-daemon clamdscan clamav-testfiles clamav-freshclam clamav-milter Architecture: source all amd64 Version: 0.98.7+dfsg-0+deb8u1 Distribution: stable Urgency: high Maintainer: ClamAV Team <pkg-clamav-devel@lists.alioth.debian.org> Changed-By: Sebastian Andrzej Siewior <sebastian@breakpoint.cc> Description: clamav - anti-virus utility for Unix - command-line interface clamav-base - anti-virus utility for Unix - base package clamav-daemon - anti-virus utility for Unix - scanner daemon clamav-dbg - debug symbols for ClamAV clamav-docs - anti-virus utility for Unix - documentation clamav-freshclam - anti-virus utility for Unix - virus database update utility clamav-milter - anti-virus utility for Unix - sendmail integration clamav-testfiles - anti-virus utility for Unix - test files clamdscan - anti-virus utility for Unix - scanner client libclamav-dev - anti-virus utility for Unix - development files libclamav6 - anti-virus utility for Unix - library Closes: 778406 778445 779758 781088 783720 Changes: clamav (0.98.7+dfsg-0+deb8u1) stable; urgency=high . [ Andreas Cadhalpun ] * Fix variable name mismatch in clamav-milter.postinst in order to make preseeding work correctly. (Closes: #778445) * Rename DEBCONFILE to DEBCONFFILE in clamav-freshclam.postinst making it consistent with the other postinst scripts. * Build against libsystemd-dev. (Closes: #779758) * Drop 'XS-Testsuite: autopkgtest' from debian/control. Debhelper automatically adds the Testsuite field. This fixes the lintian warning xs-testsuite-header-in-debian-control. * Shorten debian/copyright. This fixes some lintian warnings: - dep5-copyright-license-name-not-unique - wildcard-matches-nothing-in-dep5-copyright - unused-file-paragraph-in-dep5-copyright * Use pathfind to avoid hardcoding paths. This fixes command-with-path-in-maintainer-script lintian warnings. * Fix syntax errors in clamav-freshclam.postinst. Thanks piuparts! * Fix cleanup on purge in clamav-base.postrm. * Use SocketUser, SocketGroup and RemoveOnStop systemd socket options instead of using ExecStartPost and ExecStopPost for that. * Respect clamav-daemon's LocalSocket* options with the systemd unit by extending the clamav-daemon.socket file appropriately, when running dpkg-reconfigure clamav-daemon. (Closes: #783720) * Disable this extendend configuration, when handling the configuration file with debconf is disabled. * Disable clamav-daemon.socket in prerm script. . [ Sebastian Andrzej Siewior ] * Replace ” with " in debian/common_functions (Closes: #781088) * Drop __DATE__ from tfm to make the package build reproducible with -Werror=date-time. With this change faketime is no longer required. * Import new upstream: - Improvements to PDF processing: decryption, escape sequence handling, and file property collection. - Scanning/analysis of additional Microsoft Office 2003 XML format. - Fix infinite loop condition on crafted y0da cryptor file. Identified and patch suggested by Sebastian Andrzej Siewior. CVE-2015-2221. - Fix crash on crafted petite packed file. Reported and patch supplied by Sebastian Andrzej Siewior. CVE-2015-2222. - Fix false negatives on files within iso9660 containers. This issue was reported by Minzhuan Gong. - Fix a couple crashes on crafted upack packed file. Identified and patches supplied by Sebastian Andrzej Siewior. - Fix a crash during algorithmic detection on crafted PE file. Identified and patch supplied by Sebastian Andrzej Siewior. - Fix an infinite loop condition on a crafted "xz" archive file. This was reported by Dimitri Kirchner and Goulven Guiheux. CVE-2015-2668. - Fix compilation error after ./configure --disable-pthreads. Reported and fix suggested by John E. Krokes. - Apply upstream patch for possible heap overflow in Henry Spencer's regex library. CVE-2015-2305 (Closes: #778406). - Fix crash in upx decoder with crafted file. Discovered and patch supplied by Sebastian Andrzej Siewior. CVE-2015-2170. - Fix segfault scanning certain HTML files. Reported with sample by Kai Risku. - Improve detections within xar/pkg files. * update GPG key used to verify releases to get uscan/get_orig.sh working again. * update symbol version for cl_retflevel due to CL_FLEVEL change. Checksums-Sha1: 4f8a3473c07d8a867a3d40a78acfc53ae0383ced 3103 clamav_0.98.7+dfsg-0+deb8u1.dsc d00df0b36ca5ef72518e891e5cb2bdf7ffbf9b9c 8322932 clamav_0.98.7+dfsg.orig.tar.xz db1cdda13f1f6b30dd051f31809a4277a9efcd6b 242188 clamav_0.98.7+dfsg-0+deb8u1.debian.tar.xz fadd8527827ec136c902b7268e7480edd6306c13 283210 clamav-base_0.98.7+dfsg-0+deb8u1_all.deb 5e32d6635434a4bba85bcfc86a643c56f78b24bb 883632 clamav-docs_0.98.7+dfsg-0+deb8u1_all.deb 9d4839e7c735732b8c1d9d6a6485ece66362c1a5 2431586 clamav-dbg_0.98.7+dfsg-0+deb8u1_amd64.deb b7b71a9b38f60a7b9b0a4c9c71adc7fcf8b21767 324672 clamav_0.98.7+dfsg-0+deb8u1_amd64.deb 388d63f7af4bb0e45d4535a6035fdfbe3eba65a9 244372 libclamav-dev_0.98.7+dfsg-0+deb8u1_amd64.deb 81cf4e3f52be341db13da439852af7f721305ed7 925998 libclamav6_0.98.7+dfsg-0+deb8u1_amd64.deb c20f56aaa1a4cbc57bdb815afc931481bdead188 420898 clamav-daemon_0.98.7+dfsg-0+deb8u1_amd64.deb ebe6511c58a236c14b6ae3b12d416357b4b316c8 297568 clamdscan_0.98.7+dfsg-0+deb8u1_amd64.deb d887dc49ed7f2f3341ec27fe2aafe9d85802de97 3096342 clamav-testfiles_0.98.7+dfsg-0+deb8u1_all.deb 58cc5ba582c0dfc3f0632a95e680fc2bd5350ed3 348190 clamav-freshclam_0.98.7+dfsg-0+deb8u1_amd64.deb 4752d420319a4e5fc5662977cb0e1bc058c8f383 387118 clamav-milter_0.98.7+dfsg-0+deb8u1_amd64.deb Checksums-Sha256: 82d2f957ea83a7dd8f4f16140098b99ffe4724acc514daa0f852250590fcad2e 3103 clamav_0.98.7+dfsg-0+deb8u1.dsc 3a153ccdde90702dc175bd251784b66f09431b517da4ca8c99407ecd3e295fa5 8322932 clamav_0.98.7+dfsg.orig.tar.xz aa6c16cfcdf6d8eac26348926e493524360aa5abaf3eeaf9d9e0b8c67949e3d1 242188 clamav_0.98.7+dfsg-0+deb8u1.debian.tar.xz 560ad980d4eae99f9828d2a4d23d66e148268e43e730e9c05263c782eb54b59c 283210 clamav-base_0.98.7+dfsg-0+deb8u1_all.deb 2e688dd5958b67d6fd3c733025ad85a20e6c7355c012ace23ab831c4f417beb0 883632 clamav-docs_0.98.7+dfsg-0+deb8u1_all.deb 6ab58a8ba33f600b8b8ba4f1787ca9c2bbf7de40a9ab5f685e6090166da6395c 2431586 clamav-dbg_0.98.7+dfsg-0+deb8u1_amd64.deb c322ccd4f4d09e57adfdff2f4e582c4aa6618f89d0d33207d4dc8e46e6b903d2 324672 clamav_0.98.7+dfsg-0+deb8u1_amd64.deb d87374c9f17e444edca57dba262c0c73fc6965b29ad2dc2885a8c957eeb20f4a 244372 libclamav-dev_0.98.7+dfsg-0+deb8u1_amd64.deb e3f3d035dff7b3b4901f99ba7cb82318f24a46fe69142899c47a055fb605fda3 925998 libclamav6_0.98.7+dfsg-0+deb8u1_amd64.deb 093fcafcdf3dd7a313a4710f9d520cc64aa999cd86d2af1836c1b1d2f5fc953c 420898 clamav-daemon_0.98.7+dfsg-0+deb8u1_amd64.deb c4f5c28027bf40a89d1054275cf84947605ea7a48cf5faa6ec3b128ae18e1b18 297568 clamdscan_0.98.7+dfsg-0+deb8u1_amd64.deb 0398231ad84da583f302062d24e5b2b0bc2574abff65146b78e9d49b8502a8b4 3096342 clamav-testfiles_0.98.7+dfsg-0+deb8u1_all.deb 666026f42603d4177859d3ccdd46dbfead2202c88261260fe165072b35dc7673 348190 clamav-freshclam_0.98.7+dfsg-0+deb8u1_amd64.deb 25bd24c7b246eb61ff2489d5d5f18c98b24d484a50d4126a08239a4bdc25973b 387118 clamav-milter_0.98.7+dfsg-0+deb8u1_amd64.deb Files: 9e1841fabc2a0c773d738a48eef42ffa 3103 utils optional clamav_0.98.7+dfsg-0+deb8u1.dsc 7a012088d4389bd3ac2ac35442b98d37 8322932 utils optional clamav_0.98.7+dfsg.orig.tar.xz 3e6e3b0aa9469b01afd2df00032d4ffb 242188 utils optional clamav_0.98.7+dfsg-0+deb8u1.debian.tar.xz b673f8e8d57f6a03305936070990dd29 283210 utils optional clamav-base_0.98.7+dfsg-0+deb8u1_all.deb 10fad5c8cb1cc31a679f95c1b02ac494 883632 doc optional clamav-docs_0.98.7+dfsg-0+deb8u1_all.deb a708f2fa19bde4a2ba8f0962aff424d9 2431586 debug extra clamav-dbg_0.98.7+dfsg-0+deb8u1_amd64.deb 2d6b49521323ecff7128d65a052f0d06 324672 utils optional clamav_0.98.7+dfsg-0+deb8u1_amd64.deb 0814abc809685c59c1a4c9692f3e20df 244372 libdevel optional libclamav-dev_0.98.7+dfsg-0+deb8u1_amd64.deb ac681117183648854fa7a9234c29a421 925998 libs optional libclamav6_0.98.7+dfsg-0+deb8u1_amd64.deb ab6122f1e8639438faf2a3cc4285c7c6 420898 utils optional clamav-daemon_0.98.7+dfsg-0+deb8u1_amd64.deb eb0dac6ea43214ffefeec105d5f94a31 297568 utils optional clamdscan_0.98.7+dfsg-0+deb8u1_amd64.deb 1696b6a736f1ec11c13c996e64422699 3096342 utils optional clamav-testfiles_0.98.7+dfsg-0+deb8u1_all.deb ba090e5d5cb97ababc7ed1c154ce01ed 348190 utils optional clamav-freshclam_0.98.7+dfsg-0+deb8u1_amd64.deb 3635b7bfcb180ed16c80cfdf04591a3e 387118 utils extra clamav-milter_0.98.7+dfsg-0+deb8u1_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJVRj+6AAoJEHjX3vua1ZrxZuoP/1RNUBWfyC/mzNopez29GiOi 9IEKQM6uPo/IkaU8Vyy9lZ/gIKOr+8GgA/3qJYGuwo6l+uAIBPN8MTJhEZWrbTHa qfKGYDnidFw8F5MdTEYuKJgdjZEXSM8Nl1vlk5lehRKhycbfQdjazOXBLcZsOkJd mqBKbQObdz43gNZIlZILmrXAczNWh679yA2y0UxLAcszkFbd5VKuqB7y1Use4dM2 INKycGu6IZu+aq+IVkyZPyo1HqjTGwmiKpsxK3O9o5D5VewJgHa5RIhHBmUqLeCa RyeezdrCL3b/NmV7P1E/fTiNMj6vEMWC1ObcJVOHs9Dm7k6Al4xG/8+/VQn8dNMT PblApcVFKjIEGQjLq9o+k1GHySuPSMA209LS3mJx3OT6Zcv1c05Potd0+Bcq0gf4 1CD2pUSs0bYoIgYCwjsbFGPvd9TC6qOWU7zfQidCVu40H6dEd4rkReGDpUa6ubYo Vh7CDqV4D0UbbABVrdiLlgKXqXhMUCHOCw97UJZuMzs753E6mQPGNivegfkvz/r7 xOQ52PGzOcjJJKYGc3xoe8ZMQbC43l0jRuir/faw9ufmZiSViqdPQ6m184vIlSIo 97QztNCecZE8noyWpJaWz7w0BOS9UxtEUAQ5nMUTiWuo1oKO4UXNYIK6um/bqE3b aDX5dZX87RFOWnFgIp8M =EFre -----END PGP SIGNATURE-----