Bug 612833 - *SECURITY*PROBLEM*: ClamAV is OUTDATED
Summary: *SECURITY*PROBLEM*: ClamAV is OUTDATED
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: clamav
Version: 13
Hardware: All
OS: Linux
low
urgent
Target Milestone: ---
Assignee: Nick Bebout
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2010-07-09 08:00 UTC by Eduard Vopicka
Modified: 2010-08-19 01:07 UTC (History)
5 users (show)

Fixed In Version: clamav-0.96.1-1401.fc14
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2010-08-19 01:07:29 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Eduard Vopicka 2010-07-09 08:00:43 UTC
Description of problem:
=======================
ClamAV is OUTDATED !!! Please consider to upgrade to current version. IMHO this is *SECURITY*PROBLEM* because of ClamAV is antivirus software.

An excerpt from http://www.clamav.net/lang/en/support/faq/faq-upgrade/:
    *  What does WARNING: Current functionality level = 1, required = 2 mean?
    * The functionality level of the database determines which scanner engine version is required to use all of its signatures. If you don’t upgrade immediately you will be missing the latest viruses.

    *  What does Your ClamAV installation is OUTDATED mean?
    * You’ll get this message whenever a new version of ClamAV is released. In order to detect all the latest viruses, it’s not enough to keep your database up to date. You also need to run the latest version of the scanner. You can download the sources of the latest release from our website. Upgrade instructions are on the Wiki. If you are afraid to break something while upgrading, use the precompiled packages for your operating system/distribution. Remember: running the latest stable release also improves stability.


And Fedora13 does currently have:
Current functionality level = 44, recommended = 53

Version-Release number of selected component (if applicable):
=============================================================
clamav-0.95.3-1301.fc13.i686


How reproducible:
=================
Easily, always.

Steps to Reproduce:
===================
1. Run freshclam from command line, watch output.
2. run clamscan , look at the first few lines of output.

Actual results:
===============
[root@v5218c3 ~]# freshclam
ClamAV update process started at Fri Jul  9 09:42:02 2010
WARNING: Your ClamAV installation is OUTDATED!
WARNING: Local version: 0.95.3 Recommended version: 0.96.1
DON'T PANIC! Read http://www.clamav.net/support/faq
     ...truncated...
WARNING: Your ClamAV installation is OUTDATED!
WARNING: Current functionality level = 44, recommended = 53
DON'T PANIC! Read http://www.clamav.net/support/faq
Database updated (806897 signatures) from database.clamav.net
[root@v5218c3 ~]# date
Fri Jul  9 09:42:45 CEST 2010
[root@v5218c3 ~]# 


Expected results:
=================
No warnings


Additional info:
================
It is my personal opinion that ClamAV in Fedora is not updated frequently enough and this is niot the first time this problem manifasts itself.

Comment 1 Jan ONDREJ 2010-07-12 13:01:40 UTC
clamav-0.96.1-1300.fc13.i686 is available in Fedora 13 updates-testing repository. I think this should be released as stable for F13 and may be later for F12 too. Anybody can confirm this?

Can you try to update to this version (may be also available for F12)?

If yes, please try:
  yum update --enablerepo=updates-testing clamav

May be some applications need to be rebuild for this new version, but I think no so much.

Comment 2 Eduard Vopicka 2010-07-12 20:02:07 UTC
OK, if it may help with testing, I can do so.

Installs w/o any trouble on my up-to-date F13/i686. In fact, I have installed/updated clamav* with exception of naturally conflicting clamav-data.

Scanend my PATH direstories pluz directory with lots of windows executables and archoves w/o any apparent problem.

And, just for fun, it is able to detect at least something:

[root@lin ~]# clamscan -v /tmp/eicar*
Scanning /tmp/eicar.com
/tmp/eicar.com: Eicar-Test-Signature FOUND
Scanning /tmp/eicar.com.txt
/tmp/eicar.com.txt: Eicar-Test-Signature FOUND
Scanning /tmp/eicar_com.zip
/tmp/eicar_com.zip: Eicar-Test-Signature FOUND

----------- SCAN SUMMARY -----------
Known viruses: 806470
Engine version: 0.96.1
Scanned directories: 0
Scanned files: 3
Infected files: 3
Data scanned: 0.00 MB
Data read: 0.00 MB (ratio 0.00:1)
Time: 15.806 sec (0 m 15 s)
[root@lin ~]#

Comment 3 Fedora Update System 2010-08-11 01:19:19 UTC
clamav-0.96.1-1401.fc13 has been submitted as an update for Fedora 13.
http://admin.fedoraproject.org/updates/clamav-0.96.1-1401.fc13

Comment 4 Fedora Update System 2010-08-11 01:20:48 UTC
clamav-0.96.1-1401.fc13 has been submitted as an update for Fedora 13.
http://admin.fedoraproject.org/updates/clamav-0.96.1-1401.fc13

Comment 5 Fedora Update System 2010-08-11 01:22:39 UTC
clamav-0.96.1-1401.fc14 has been submitted as an update for Fedora 14.
http://admin.fedoraproject.org/updates/clamav-0.96.1-1401.fc14

Comment 6 Fedora Update System 2010-08-11 01:36:30 UTC
clamav-0.96.1-1401.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/clamav-0.96.1-1401.fc12

Comment 7 Fedora Update System 2010-08-11 07:27:22 UTC
clamav-0.96.1-1401.fc12 has been pushed to the Fedora 12 testing repository.  If problems still persist, please make note of it in this bug report.
 If you want to test the update, you can install it with 
 su -c 'yum --enablerepo=updates-testing update clamav'.  You can provide feedback for this update here: http://admin.fedoraproject.org/updates/clamav-0.96.1-1401.fc12

Comment 8 Fedora Update System 2010-08-11 07:30:32 UTC
clamav-0.96.1-1401.fc13 has been pushed to the Fedora 13 testing repository.  If problems still persist, please make note of it in this bug report.
 If you want to test the update, you can install it with 
 su -c 'yum --enablerepo=updates-testing update clamav'.  You can provide feedback for this update here: http://admin.fedoraproject.org/updates/clamav-0.96.1-1401.fc13

Comment 9 Fedora Update System 2010-08-19 01:07:09 UTC
clamav-0.96.1-1401.fc14 has been pushed to the Fedora 14 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.