ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
Secunia: DoS possible @ new Version
ackermann


Joined: 18 Feb 2006
Posts: 0
Reply with quote
There you can read the security message:

https://secunia.com/advisories/24187/
View user's profileSend private message
alch
Site Admin

Joined: 27 Nov 2005
Posts: 0
Reply with quote
we are beta-testing clamwin 0.90 and will release it asap
View user's profileSend private message
Vulnerabilities
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
I believe I counted about 6 publicized vulnerabilities in Kaspersky's product in 2006, so this isn't too bad. Some of this stuff isn't that likely to be exploited. I've always felt like ClamWin was chewing on those CAB files, however, like an old man without any teeth!

Regards,
View user's profileSend private message
ackermann


Joined: 18 Feb 2006
Posts: 0
Reply with quote
The problem I see is that Clam(AV!) is a very popular server application that's used by many providers and email services. So I think that more bad guys are interested in hacking these popular server software than some kaspersky application that is used on home-pc's mostly.

Could be that I am wrong but it doesn't feel good to me that my only security software is on the spotlight of secunia.com
View user's profileSend private message
Clam Vulnerability
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
You're right. I'm just a personal computer user, so I sometimes forget that ClamAV is used by some pretty large email service providers. Even considering that, however, most of those exploits need a "specially crafted" file according to the notices I see. I don't believe that all malware writers are capable of crafting such files. We personal users can exclude CAB files and other extensions that might be vulnerable from ClamWin scans until we hear the problem has been fixed. Finally, all personal users should also be using a real-time commercial scanner--there are several good ones that are free, until ClamAV/ClamWin is no longer beta software. Hopefull that won't be too long. 90,000 signatures is getting out of the beta category, eh?

I wish those academics/experts/consultants that publicize security vulnerables would just keep their mouths shut--at least in public. There's no sense in telling malware writers what/how to do it--let them have to work like the rest of us.

Regards,
View user's profileSend private message
Re: Clam Vulnerability
ackermann


Joined: 18 Feb 2006
Posts: 0
Reply with quote
GuitarBob wrote:

I wish those academics/experts/consultants that publicize security vulnerables would just keep their mouths shut--at least in public. There's no sense in telling malware writers what/how to do it--let them have to work like the rest of us.

Regards,


I'll never understand why such exploits are published on those sites as long as they ain't patched.
In my opinion it would be good enough to tell 'em to the developer-team of the program.
View user's profileSend private message
Patches
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
You wrote:

"I'll never understand why such exploits are published on those sites as long as they ain't patched.
In my opinion it would be good enough to tell 'em to the developer-team of the program."

That would be the ethical thing to do, but I guess it shows the "abilities" of these security "consultants."
In this case, they may have told Clam ahead of time, because they mentioned Version 0.90 fixed things.

Regards,
View user's profileSend private message
Secunia: DoS possible @ new Version
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic