lp:debian/wheezy/clamav

Created by James Westby and last modified
Get this branch:
bzr branch lp:debian/wheezy/clamav
Members of Ubuntu branches can upload to this branch. Log in for directions.

Related bugs

Related blueprints

Branch information

Owner:
Ubuntu branches
Status:
Development

Recent revisions

40. By Sebastian Andrzej Siewior <email address hidden>

[ Andreas Cadhalpun ]
* Fix variable name mismatch in clamav-milter.postinst in order to
  make preseeding work correctly. (Closes: #778445)
* Drop 'XS-Testsuite: autopkgtest' from debian/control.
  Debhelper automatically adds the Testsuite field.
  This fixes the lintian warning xs-testsuite-header-in-debian-control.
* Fix cleanup on purge in clamav-base.postrm.

[ Sebastian Andrzej Siewior ]
* Replace ” with " in debian/common_functions (Closes: #781088)
* Import new upstream:
  - Improvements to PDF processing: decryption, escape sequence
    handling, and file property collection.
  - Scanning/analysis of additional Microsoft Office 2003 XML format.
  - Fix infinite loop condition on crafted y0da cryptor file. Identified
    and patch suggested by Sebastian Andrzej Siewior. CVE-2015-2221.
  - Fix crash on crafted petite packed file. Reported and patch
    supplied by Sebastian Andrzej Siewior. CVE-2015-2222.
  - Fix false negatives on files within iso9660 containers. This issue
    was reported by Minzhuan Gong.
  - Fix a couple crashes on crafted upack packed file. Identified and
    patches supplied by Sebastian Andrzej Siewior.
  - Fix a crash during algorithmic detection on crafted PE file.
    Identified and patch supplied by Sebastian Andrzej Siewior.
  - Fix an infinite loop condition on a crafted "xz" archive file.
    This was reported by Dimitri Kirchner and Goulven Guiheux.
    CVE-2015-2668.
  - Fix compilation error after ./configure --disable-pthreads.
    Reported and fix suggested by John E. Krokes.
  - Apply upstream patch for possible heap overflow in Henry Spencer's
    regex library. CVE-2015-2305 (Closes: #778406).
  - Fix crash in upx decoder with crafted file. Discovered and patch
    supplied by Sebastian Andrzej Siewior. CVE-2015-2170.
  - Fix segfault scanning certain HTML files. Reported with sample by
    Kai Risku.
  - Improve detections within xar/pkg files.
* update GPG key used to verify releases to get uscan/get_orig.sh working
  again.
* update symbol version for cl_retflevel due to CL_FLEVEL change.

39. By Sebastian Andrzej Siewior <email address hidden>

Add "libmspack-qtmd-fix-frame_end-overflow" to avoid endless-loop on
special crafted quantum compressed cab files. Patch suggested by Andreas
Cadhalpus (Closes: #773318).

38. By Scott Kitterman

[ Scott Kitterman ]
* debian/patches/0002-Fix-STAT64-definition-and-add-missing-includes.patch:
  Removed, because the remaining changes are not needed to fix FTBFS and
  upstream recommends drop due to potential issues with scanning large
  files.

[ Andreas Cadhalpun ]
* Fix debian/watch to properly detect release candidates.
* Add patches to fix building on Hurd:
   - 0008-Fix-compiling-on-Hurd.patch
   - 0009-Workaround-a-bug-in-libc-on-Hurd.patch
* Fix 0004-Fix-FTBFS-with-LLVM-3.1-3.4.patch to correctly detect the
  new LLVM version scheme X.Y.Z (instead of X.Y).
* Add versioned dependencies on procps (for 'pkill -F') and on dpkg
  (for 'start-stop-daemon --status').
* Remove useless code from debian/freshclam.init.in.
* Avoid creation of an empty freshclam.pid file.
* Switch the watchfile to look at github.com, because the sf.net
  website doesn't work correctly at the moment, see #752384.
* Add DEP-5 header with Files-Excluded field to debian/copyright
  in order to let uscan remove unneeded files.

[ Julien Patriarca ]
* Updated French Debconf template translation (Closes: #752388)

[ Sebastian Andrzej Siewior ]
* Add 0010-Call-cl_initialize_crypto-in-cl_init.patch from upstream. The
  cl_initialize_crypto() will now be invoked within libclamav in cl_init()
  so there is now no need to force third party to invoke that function on
  their own.

37. By Scott Kitterman

[ Sebastian Andrzej Siewior ]
* Postinst scripts: fix empty access and broken freshclam.conf in
  clamav-base.postinst.in and clamav-freshclam.postinst.in (Closes: #741675,
  #742034)
* Postinst scripts: fix quoting

[ Andreas Cadhalpun ]
* Add templates and adapt postinst and config scripts for the new options
  in 0.98 to fix the creation of the configuration files (Closes: #741675,
  #742034)
* Reset new options to default to fix breakage in previous upload
* Automatically updated translation files

36. By Scott Kitterman

* New upstream release
* Update libclamav6 lintian override to match updated soversion
* Urgency medium due to security fixes

35. By Scott Kitterman

* New upstream release
* Update libclamav6 lintian override to match updated soversion
* Urgency medium due to security fixes

34. By Scott Kitterman

* New upstream release (Closes: #689487)
* Update libclamav6 lintian override to match updated soversion

33. By Scott Kitterman

* Urgency medium for RC bug fix the addressess regression from 0.97.3
* Add changes from upstream commit 6a879ad98460303b23a6fc119769a3b463a902f8
  to fix unpack errors for various compressed files including some .bz2,
  .xls, .doc, and PDF (Closes: #684697)

32. By Scott Kitterman

* Drop /var/run/clamav from the directories shipped in clamav-base (policy
  9.1.4) and trust it will get cleaned up on boot
  - Thanks to Andreas Beckmann for the cluebat

31. By Scott Kitterman

* Drop postrm snippets from clamav-base, clamav-freshclam, clamav-daemon,
  and clamav-milter that remove /var/log/clamav, /var/lib/clamav,
  /var/run/clamav, and /etc/clamav and and let dpkg remove the directories
  once they are empty in order to fix problems with directory removal by a
  package that did not own the directory (Closes: #681960)
* Add /var/run/clamav to directories shipped by clamav-base so dpkg cleanup
  will work for it too.

Branch metadata

Branch format:
Branch format 7
Repository format:
Bazaar repository format 2a (needs bzr 1.16 or later)
Stacked on:
lp:debian/clamav
This branch contains Public information 
Everyone can see this information.

Subscribers