[clamav-users] clamav-0.98.3 does not pass vulnerability scan

Matus UHLAR - fantomas uhlar at fantomas.sk
Tue May 20 08:54:17 UTC 2014


On 20.05.14 16:22, anctop wrote:
>Both clamav-milter & clamd were still working after the "attack" by the scan.
>
>Our config files assume default values for recursive scanning.
>I'd like to know if the recursion depth is lowered, will clamd fail to
>detect those viruses deeply hidden in nested directories ?

Well, no idea. The scanning will finish with exit code indicating that it
was not able to scan the whole structure.

There used to be ArchiveBlockMax option that instructed clamav to report
infection (with pseudo virus name) but it was removed and I don't see the
replacement for it.

I also don't see how should clamav-milter behave here.

Maybe I should try to test scanning archive of 16 nested directories to see
the results...

-- 
Matus UHLAR - fantomas, uhlar at fantomas.sk ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
I intend to live forever - so far so good. 



More information about the clamav-users mailing list