AIX Open Source

 View Only
Expand all | Collapse all

ClamAV 1.0 required

  • 1.  ClamAV 1.0 required

    Posted Tue February 21, 2023 06:08 AM

    Hi

    We are running ClamAV 0.104 but see that DB downloads will be unavailable for that version soon.


    Do you have a ETA for the next release?


    0.103 is LTS but not available from the AIX Toolbox so we suggesting version 1.0 which is also LTS.



    ------------------------------
    Hector Speight
    ------------------------------


  • 2.  RE: ClamAV 1.0 required

    Posted Tue February 21, 2023 08:54 AM

    Thanks for reporting this. We will look into 1.0 version. 



    ------------------------------
    Ayappan P
    ------------------------------



  • 3.  RE: ClamAV 1.0 required

    Posted Wed February 22, 2023 08:28 AM

    This may affect certain security compliance requirements for users.  We are looking at deploying it ourselves for that reason so glad I noticed this thread and am now aware of it.

    Thanks,

    Chris



    ------------------------------
    Chris Horn
    ------------------------------



  • 4.  RE: ClamAV 1.0 required

    Posted Tue March 14, 2023 11:41 AM

    Hello Ayappan 

    Do you have the ETA for when you can look at this

    Thanks
    Hector



    ------------------------------
    Hector Speight
    ------------------------------



  • 5.  RE: ClamAV 1.0 required

    Posted Wed March 15, 2023 08:40 AM

    We are looking into the 1.0 version , right now. I can't provide a ETA now. I will have more update next week. 



    ------------------------------
    Ayappan P
    ------------------------------



  • 6.  RE: ClamAV 1.0 required

    Posted Thu March 16, 2023 05:31 AM

    The ClamAV 1.0 version requires rust compiler which is not yet available in AIX. So we will go with 0.103 LTS version for the time being. 



    ------------------------------
    Ayappan P
    ------------------------------



  • 7.  RE: ClamAV 1.0 required

    Posted Mon March 27, 2023 05:42 AM

    Ayappan

    I'm checking if you have an estimate when 0.103 LTS will be available for download from the AIX toolbox

    Regards



    ------------------------------
    Hector Speight
    ------------------------------



  • 8.  RE: ClamAV 1.0 required

    Posted Mon March 27, 2023 10:25 AM

    We are working on it. We will try to publish it in a couple of weeks



    ------------------------------
    Ayappan P
    ------------------------------



  • 9.  RE: ClamAV 1.0 required

    Posted Fri April 14, 2023 04:23 AM

    Ayappan are you any closer to having a delivery date



    ------------------------------
    Hector Speight
    ------------------------------



  • 10.  RE: ClamAV 1.0 required

    Posted Fri April 14, 2023 04:32 AM

    We have built & tested the 0.103.8 clamav version. Since this is major version update in Toolbox, there is some legal process involved before publishing it which might take some time. I don't have any ETA right now but hopefully it can be published before April end. 



    ------------------------------
    Ayappan P
    ------------------------------



  • 11.  RE: ClamAV 1.0 required

    Posted Mon June 12, 2023 05:11 AM

    Hi

    Checking on the progress of the legal process and if a release date has been finalised.

    Thanks



    ------------------------------
    Hector Speight
    ------------------------------



  • 12.  RE: ClamAV 1.0 required

    Posted Mon June 12, 2023 06:56 AM

    We have everything in place now. It will be available this week. 



    ------------------------------
    Ayappan P
    ------------------------------



  • 13.  RE: ClamAV 1.0 required

    Posted Tue July 04, 2023 09:36 AM

    clamav 0.103.8 is made available in Toolbox recently. 



    ------------------------------
    Ayappan P
    ------------------------------



  • 14.  RE: ClamAV 1.0 required

    Posted Thu July 06, 2023 07:44 AM

    Thank you



    ------------------------------
    Hector Speight
    ------------------------------



  • 15.  RE: ClamAV 1.0 required

    Posted Tue May 07, 2024 10:46 AM

    clamav 0.103 will be EOS in September 2024

    Please can you make LTS version 1.0 available.



    ------------------------------
    Hector Speight
    ------------------------------



  • 16.  RE: ClamAV 1.0 required

    Posted Wed May 08, 2024 03:47 AM

    Hi Hector,

    We will try to release this version or a higher version of Clamav after the release of Rust 1.77.0 in the toolbox, which will happen in 2Q, since this version of clamav depends on rust. 



    ------------------------------
    Aditya Kamath
    ------------------------------



  • 17.  RE: ClamAV 1.0 required

    Posted Tue June 25, 2024 04:50 AM

    Hi Aditya do you have an ETA we can plan against?



    ------------------------------
    Hector Speight
    ------------------------------



  • 18.  RE: ClamAV 1.0 required

    Posted Fri August 02, 2024 04:46 AM

    Do you have any ETA for us please?



    ------------------------------
    Hector Speight
    ------------------------------



  • 19.  RE: ClamAV 1.0 required

    Posted Tue August 06, 2024 03:40 AM

    We are building & testing it now. If everything goes smoothly, probably before end of next week (16th August ) it can be made available in AIX Toolbox. 



    ------------------------------
    Ayappan P
    ------------------------------



  • 20.  RE: ClamAV 1.0 required

    Posted Wed August 14, 2024 10:05 AM

    Hi @Hector Speight,

    We encountered a small issue in Clamav 1.0.6, for which we are currently resolving your request. This will take one more week than what Ayappan said.



    ------------------------------
    Aditya Kamath
    ------------------------------



  • 21.  RE: ClamAV 1.0 required

    Posted Mon September 02, 2024 12:56 AM

    @Hector Speight

    Please update to clamav 1.0.6, the LTS version currently being used by the clamav community, by running "dnf upgrade clamav."

    I appreciate your patience. 

    You might want to refer the article here if you encounter some issues during install.

    https://community.ibm.com/community/user/power/discussion/regarding-clamav-and-cryptography-updates#bm1a526a84-bbf2-4182-85b5-e847658c895e



    ------------------------------
    Aditya Kamath
    ------------------------------



  • 22.  RE: ClamAV 1.0 required

    Posted Thu September 26, 2024 09:16 AM

    Hello Aditya.

     

        I am receiving the following:

    WARNING: Local version: 0.103.11 Recommended version: 0.103.12

    It appears there is a new security issue that is fixed in 0.103.12. Do you know when this level will be available in the IBM Toolbox?  Thanks.

     

              Regards,

               Dave 



    ------------------------------
    David Marstiller
    ------------------------------



  • 23.  RE: ClamAV 1.0 required

    Posted Thu September 26, 2024 09:21 AM

    Thank you for the update. However, version 1.0.6 also has the same security issues. ClamAV suggests going to 1.0.7 level. When will the IBM Toolbox have the new 1.0.7 level?

     

             Regards,

    David S. Marstiller

    OCIO/SDS/AIX Platform Services

    Contractor – Leidos

    Senior Systems Engineer

     

    David.S.Marstiller@usdoj.gov

    2CON – 3W-312

    O:202.307.6972

    C:240-543-9823

    Work Schedule: M-Th 7:30AM – 5:00PM, Fri 7:30 – 12:00

     

    If not available please contact Paul Ingson at 7-6952 or Yaojun Shi at 7-5354

     






  • 24.  RE: ClamAV 1.0 required

    Posted Thu September 26, 2024 11:05 AM

    Incase you were unaware of the following Security Issues with ClamAV:

    ClamAV 0.103.12 is a patch release with the following fixes:

    • CVE-2024-20506: Changed the logging module to disable following symlinks on Linux and Unix systems so as to prevent an attacker with existing access to the 'clamd' or 'freshclam' services from using a symlink to corrupt system files.

      This issue affects all currently supported versions. It will be fixed in:

      • 1.4.1
      • 1.3.2
      • 1.0.7
      • 0.103.12

      Thank you to Detlef for identifying this issue.

    • CVE-2024-20505: Fixed a possible out-of-bounds read bug in the PDF file parser that could cause a denial-of-service condition.

      This issue affects all currently supported versions. It will be fixed in:



    ------------------------------
    David Marstiller
    ------------------------------



  • 25.  RE: ClamAV 1.0 required

    Posted Wed October 02, 2024 07:00 AM

    Hello Ayappan 

         Do you have a timeframe of when 0.103.12 will be available in the Toolbox? Your help is appreciated.

          Thanks,

           Dave 



    ------------------------------
    David Marstiller
    ------------------------------



  • 26.  RE: ClamAV 1.0 required

    Posted Fri October 04, 2024 03:42 AM
    Edited by Aditya Kamath Fri October 04, 2024 07:00 AM

    Hi David,

    Thank you for the report. We will update Clamav to 1.0.7. Expect a release in the 3rd week of October.

    Update below this thread [Expected by next tuesday]



    ------------------------------
    Aditya Kamath
    ------------------------------



  • 27.  RE: ClamAV 1.0 required

    Posted Fri October 04, 2024 07:00 AM

    @David Marstiller By Tuesday [8/10/2024], AIX users will get the update to clamav - 1.0.7. 



    ------------------------------
    Aditya Kamath
    ------------------------------



  • 28.  RE: ClamAV 1.0 required

    Posted Fri October 04, 2024 07:05 AM

    Hello Aditya.

        Will you also be updating 0.103.12 version. We are currently at 0.103.11 version?

    Thanks for the quick follow-up to this issue. We appreciate it.

     

           Regards,

             Dave  

     



    ------------------------------
    David Marstiller
    ------------------------------



  • 29.  RE: ClamAV 1.0 required

    Posted Fri October 04, 2024 07:42 AM

    There is no plan to maintain two versions. Users are recommended to move to 1.0.X version.



    ------------------------------
    Ayappan P
    ------------------------------



  • 30.  RE: ClamAV 1.0 required

    Posted Fri October 04, 2024 07:48 AM

    Hello Ayappan.

     

              I am confused by your last response. The ToolBox currently does have support for both versions:

    clamav 0.103.11 (5.2) License RPM - 'Antivirus Toolkit'
    clamav 1.0.6 (7.2) License RPM SRPM

    'Antivirus Toolkit'

     



    ------------------------------
    David Marstiller
    ------------------------------



  • 31.  RE: ClamAV 1.0 required

    Posted Fri October 04, 2024 08:14 AM

    It's wrong with AIX Toolbox page to show like that. We will correct it. 
    Clamav 1.0.X is the current LTS version. Since the code base is in rust lang from this version onwards, this version of clamav rpm is supported from AIX 7.2 onwards. There is no plan to maintain 0.103.X anymore. 0.103.X is already reached EOL (https://docs.clamav.net/faq/faq-eol.html#version-support-matrix). 



    ------------------------------
    Ayappan P
    ------------------------------



  • 32.  RE: ClamAV 1.0 required

    Posted Mon October 07, 2024 01:25 AM



    Update: Clamav - 1.7.0 is available in the AIX toolbox.

    Kindly use dnf and update. [ dnf clean all and then dnf update clamav*]

    Thank you for reporting and request to the AIX toolbox. 



    ------------------------------
    Aditya Kamath
    ------------------------------