![]() |
| Cve_2012_0013 |
|
GuitarBob
|
I noticed several false positive submissions on the Clam submission interface for this, so they are aware of it. It should be corrected within a day or so. In the meantime, you can whitelist the file(s) in ClamWin's filters, exclude matching filenames.
Regards, |
||||||||||||
|
|
|||||||||||||
|
danq
|
I'm getting "BC.Exploit.CVE_2012_0003" on many MIDI files.
I have loads of MIDI files on my computer and can't submit them all to ClamAV. |
||||||||||||
|
|
|||||||||||||
|
GuitarBob
|
You can send email to luca at clamav dot net to ask for submisssion instructions, but if you can just submit 2 or 3 files (zipped), that will probably show the sigmaker there is a problem, and he can see that he needs to scrap the entire signature. Explain in the comments on the submission form that there are lots of other midi files being detected also. Also, please change the submission type on the submission form from "virus" to "false positive." ClamWin users are bad about not doing that, and some false positives can slip through unnoticed.
Regards, |
||||||||||||
|
|
|||||||||||||
|
user_clamwinner
|
Hello. BC.Exploit.CVE_2012_0003 on MIDI files! Why lately so many false positives in Clamwin???
|
||||||||||||
|
|
|||||||||||||
|
GuitarBob
|
Reasons For False Positives:
Malware often uses some of the same code as "good" programs. The more generic signatures can detect this code--it doesn't matter where it is. Clam has a limited number of good programs on its false positive "farm" where signatures are checked before they are released. For instance, every time Microsoft patches something, there is a new version of whatever is patched--just think of how many versions of Office that makes! With every patch series, there are some Virus false positives on Office software. There are also some new Sourcefire sigmakers helping out at Clam now. All we can do is quickly report false positives to Clam when we see them. Thankfully, ClamWin now has some protection against certain false positives that could take down the operating system. Regards, |
||||||||||||
|
|
|||||||||||||
| Cve_2012_0013 |
|
||
|
Powered by phpBB © phpBB Group
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.


