Original Message:
Sent: Wed October 02, 2024 06:59 AM
From: David Marstiller
Subject: ClamAV 1.0 required
Hello Ayappan
Do you have a timeframe of when 0.103.12 will be available in the Toolbox? Your help is appreciated.
Thanks,
Dave
------------------------------
David Marstiller
Original Message:
Sent: Thu September 26, 2024 11:05 AM
From: David Marstiller
Subject: ClamAV 1.0 required
Incase you were unaware of the following Security Issues with ClamAV:
ClamAV 0.103.12 is a patch release with the following fixes:
-
CVE-2024-20506: Changed the logging module to disable following symlinks on Linux and Unix systems so as to prevent an attacker with existing access to the 'clamd' or 'freshclam' services from using a symlink to corrupt system files.
This issue affects all currently supported versions. It will be fixed in:
- 1.4.1
- 1.3.2
- 1.0.7
- 0.103.12
Thank you to Detlef for identifying this issue.
-
CVE-2024-20505: Fixed a possible out-of-bounds read bug in the PDF file parser that could cause a denial-of-service condition.
This issue affects all currently supported versions. It will be fixed in:
------------------------------
David Marstiller
Original Message:
Sent: Thu September 26, 2024 09:19 AM
From: David Marstiller
Subject: ClamAV 1.0 required
Thank you for the update. However, version 1.0.6 also has the same security issues. ClamAV suggests going to 1.0.7 level. When will the IBM Toolbox have the new 1.0.7 level?
Regards,
David S. Marstiller
OCIO/SDS/AIX Platform Services
Contractor – Leidos
Senior Systems Engineer
David.S.Marstiller@usdoj.gov
2CON – 3W-312
O:202.307.6972
C:240-543-9823
Work Schedule: M-Th 7:30AM – 5:00PM, Fri 7:30 – 12:00
If not available please contact Paul Ingson at 7-6952 or Yaojun Shi at 7-5354
Original Message:
Sent: 9/26/2024 9:03:00 AM
From: David Marstiller
Subject: RE: ClamAV 1.0 required
Hello Aditya.
I am receiving the following:
WARNING: Local version: 0.103.11 Recommended version: 0.103.12
It appears there is a new security issue that is fixed in 0.103.12. Do you know when this level will be available in the IBM Toolbox? Thanks.
Regards,
Dave
------------------------------
David Marstiller
Original Message:
Sent: Mon September 02, 2024 12:56 AM
From: Aditya Kamath
Subject: ClamAV 1.0 required
@Hector Speight
Please update to clamav 1.0.6, the LTS version currently being used by the clamav community, by running "dnf upgrade clamav."
I appreciate your patience.
You might want to refer the article here if you encounter some issues during install.
https://community.ibm.com/community/user/power/discussion/regarding-clamav-and-cryptography-updates#bm1a526a84-bbf2-4182-85b5-e847658c895e
------------------------------
Aditya Kamath
Original Message:
Sent: Fri August 02, 2024 04:46 AM
From: Hector Speight
Subject: ClamAV 1.0 required
Do you have any ETA for us please?
------------------------------
Hector Speight
Original Message:
Sent: Tue June 25, 2024 04:50 AM
From: Hector Speight
Subject: ClamAV 1.0 required
Hi Aditya do you have an ETA we can plan against?
------------------------------
Hector Speight
Original Message:
Sent: Wed May 08, 2024 03:46 AM
From: Aditya Kamath
Subject: ClamAV 1.0 required
Hi Hector,
We will try to release this version or a higher version of Clamav after the release of Rust 1.77.0 in the toolbox, which will happen in 2Q, since this version of clamav depends on rust.
------------------------------
Aditya Kamath
Original Message:
Sent: Tue May 07, 2024 10:45 AM
From: Hector Speight
Subject: ClamAV 1.0 required
clamav 0.103 will be EOS in September 2024
Please can you make LTS version 1.0 available.
------------------------------
Hector Speight
Original Message:
Sent: Tue July 04, 2023 09:35 AM
From: Ayappan P
Subject: ClamAV 1.0 required
clamav 0.103.8 is made available in Toolbox recently.
------------------------------
Ayappan P
Original Message:
Sent: Mon June 12, 2023 06:56 AM
From: Ayappan P
Subject: ClamAV 1.0 required
We have everything in place now. It will be available this week.
------------------------------
Ayappan P
Original Message:
Sent: Mon June 12, 2023 05:11 AM
From: Hector Speight
Subject: ClamAV 1.0 required
Hi
Checking on the progress of the legal process and if a release date has been finalised.
Thanks
------------------------------
Hector Speight
Original Message:
Sent: Fri April 14, 2023 04:32 AM
From: Ayappan P
Subject: ClamAV 1.0 required
We have built & tested the 0.103.8 clamav version. Since this is major version update in Toolbox, there is some legal process involved before publishing it which might take some time. I don't have any ETA right now but hopefully it can be published before April end.
------------------------------
Ayappan P
Original Message:
Sent: Fri April 14, 2023 04:22 AM
From: Hector Speight
Subject: ClamAV 1.0 required
Ayappan are you any closer to having a delivery date
------------------------------
Hector Speight
Original Message:
Sent: Mon March 27, 2023 10:25 AM
From: Ayappan P
Subject: ClamAV 1.0 required
We are working on it. We will try to publish it in a couple of weeks
------------------------------
Ayappan P
Original Message:
Sent: Mon March 27, 2023 05:41 AM
From: Hector Speight
Subject: ClamAV 1.0 required
Ayappan
I'm checking if you have an estimate when 0.103 LTS will be available for download from the AIX toolbox
Regards
------------------------------
Hector Speight
Original Message:
Sent: Thu March 16, 2023 05:31 AM
From: Ayappan P
Subject: ClamAV 1.0 required
The ClamAV 1.0 version requires rust compiler which is not yet available in AIX. So we will go with 0.103 LTS version for the time being.
------------------------------
Ayappan P
Original Message:
Sent: Wed March 15, 2023 08:40 AM
From: Ayappan P
Subject: ClamAV 1.0 required
We are looking into the 1.0 version , right now. I can't provide a ETA now. I will have more update next week.
------------------------------
Ayappan P
Original Message:
Sent: Tue March 14, 2023 11:40 AM
From: Hector Speight
Subject: ClamAV 1.0 required
Hello Ayappan
Do you have the ETA for when you can look at this
Thanks
Hector
------------------------------
Hector Speight
Original Message:
Sent: Tue February 21, 2023 08:53 AM
From: Ayappan P
Subject: ClamAV 1.0 required
Thanks for reporting this. We will look into 1.0 version.
------------------------------
Ayappan P
Original Message:
Sent: Tue February 21, 2023 06:07 AM
From: Hector Speight
Subject: ClamAV 1.0 required
Hi
We are running ClamAV 0.104 but see that DB downloads will be unavailable for that version soon.
Do you have a ETA for the next release?
0.103 is LTS but not available from the AIX Toolbox so we suggesting version 1.0 which is also LTS.
------------------------------
Hector Speight
------------------------------