This is a multi-part message in MIME format...

------------=_1237393833-6173-3119


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Advisory MDVA-2009:018-1
http://www.mandriva.com/security/
_______________________________________________________________________

Package : clamav
Date : March 18, 2009
Affected: 2008.0, 2008.1, 2009.0, Corporate 3.0, Corporate 4.0
_______________________________________________________________________

Problem Description:

This update fixes several issues with clamav:

- update unexpectely changes location of clamd socket (#46459)
- clamav-milter was not built (#46555)
- Clamav-milter wanted to remove postfix (#46556)
- Scanning mail with clamav leaves a big temporary folder (#46642)
- Build fails if invoked with --with milter, in a configure stage
(#46554)
- Jpeg parsing denial-of-service crash in clamav 0.94-1 and earlier
(#46199)

Update:

The previous package introduced a patch that broke the clamav-milter,
this update addresses this problem:

- Bug 48633 - Fix for -Werror=format-security breaks clamav-milter
_______________________________________________________________________

References:

https://qa.mandriva.com/46459
https://qa.mandriva.com/46555
https://qa.mandriva.com/46556
https://qa.mandriva.com/46642
https://qa.mandriva.com/46554
https://qa.mandriva.com/46199
https://qa.mandriva.com/48633
_______________________________________________________________________

Updated Packages:

Mandriva Linux 2008.0:
acd48ea184e96b23de78f8d06c2420fd 2008.0/i586/clamav-0.94.2-5.1mdv2008.0.i586.rpm
f327072ce34411123e4115d8cd686da2 2008.0/i586/clamav-db-0.94.2-5.1mdv2008.0.i586.rpm
4a4915d641fc3f8de04645f29f045ef6 2008.0/i586/clamav-milter-0.94.2-5.1mdv2008.0.i586.rpm
e71d416b233f18fdd8ea307efd70de10 2008.0/i586/clamd-0.94.2-5.1mdv2008.0.i586.rpm
25f1250856a0c266320ed8ce42c540bd 2008.0/i586/libclamav5-0.94.2-5.1mdv2008.0.i586.rpm
111802223152f88f00dac65f8175732c 2008.0/i586/libclamav-devel-0.94.2-5.1mdv2008.0.i586.rpm
a77a066613490c0efdc4271858727f12 2008.0/SRPMS/clamav-0.94.2-5.1mdv2008.0.src.rpm

Mandriva Linux 2008.0/X86_64:
133815dd07f22cd232e25464f94e5579 2008.0/x86_64/clamav-0.94.2-5.1mdv2008.0.x86_64.rpm
6ad9892c1d89495ef68052f76a013854 2008.0/x86_64/clamav-db-0.94.2-5.1mdv2008.0.x86_64.rpm
606e6a5553d0f09925d4cf2741fe8c86 2008.0/x86_64/clamav-milter-0.94.2-5.1mdv2008.0.x86_64.rpm
254eb460fbc6c28e3bbf5765fc54fa80 2008.0/x86_64/clamd-0.94.2-5.1mdv2008.0.x86_64.rpm
fa2b5592750b9c3a83bab3c255456f01 2008.0/x86_64/lib64clamav5-0.94.2-5.1mdv2008.0.x86_64.rpm
1f8e9f79b79db337702d84b2ebedf0be 2008.0/x86_64/lib64clamav-devel-0.94.2-5.1mdv2008.0.x86_64.rpm
a77a066613490c0efdc4271858727f12 2008.0/SRPMS/clamav-0.94.2-5.1mdv2008.0.src.rpm

Mandriva Linux 2008.1:
6008bed3dd397e1091d0806c9fdebc6b 2008.1/i586/clamav-0.94.2-5.1mdv2008.1.i586.rpm
8c25b873b4e8c657c606e40f2f194549 2008.1/i586/clamav-db-0.94.2-5.1mdv2008.1.i586.rpm
d005ff386be3aa3d80f7610d89cc4ec1 2008.1/i586/clamav-milter-0.94.2-5.1mdv2008.1.i586.rpm
90187eff24adafab000a86a6e19be276 2008.1/i586/clamd-0.94.2-5.1mdv2008.1.i586.rpm
14b167c0a9b0b92d3ebd2f71f18efb3f 2008.1/i586/libclamav5-0.94.2-5.1mdv2008.1.i586.rpm
ad3a137194a598c9cf2619900d14edba 2008.1/i586/libclamav-devel-0.94.2-5.1mdv2008.1.i586.rpm
7746a327f8d635042c58147ef0a162ba 2008.1/SRPMS/clamav-0.94.2-5.1mdv2008.1.src.rpm

Mandriva Linux 2008.1/X86_64:
6aa451dfca0a0e2d39e971492c0df8b5 2008.1/x86_64/clamav-0.94.2-5.1mdv2008.1.x86_64.rpm
b1dbb8850ca73c98b100fb6775e8542f 2008.1/x86_64/clamav-db-0.94.2-5.1mdv2008.1.x86_64.rpm
8b2dd3324f5d12092a6a4b680dd75f7b 2008.1/x86_64/clamav-milter-0.94.2-5.1mdv2008.1.x86_64.rpm
daeab7e5c05715071a5a3f29682add82 2008.1/x86_64/clamd-0.94.2-5.1mdv2008.1.x86_64.rpm
04dea11cd59a47d52c3c74e1a2846e1b 2008.1/x86_64/lib64clamav5-0.94.2-5.1mdv2008.1.x86_64.rpm
8865fc16d55ae2a159aca3798df4747b 2008.1/x86_64/lib64clamav-devel-0.94.2-5.1mdv2008.1.x86_64.rpm
7746a327f8d635042c58147ef0a162ba 2008.1/SRPMS/clamav-0.94.2-5.1mdv2008.1.src.rpm

Mandriva Linux 2009.0:
64b40ac63b06ec7c1f88d3bcd9c8fb07 2009.0/i586/clamav-0.94.2-5.1mdv2009.0.i586.rpm
9374f2e40953c56f0c1363d61be1a5c1 2009.0/i586/clamav-db-0.94.2-5.1mdv2009.0.i586.rpm
09bcfb1b574b61e91473873a76cf464f 2009.0/i586/clamav-milter-0.94.2-5.1mdv2009.0.i586.rpm
13513590d63f29cf23a639deefcccffe 2009.0/i586/clamd-0.94.2-5.1mdv2009.0.i586.rpm
c7904d22b178725bf0638eace5a0cc45 2009.0/i586/libclamav5-0.94.2-5.1mdv2009.0.i586.rpm
e6576d7d49223769a54c4afacb161634 2009.0/i586/libclamav-devel-0.94.2-5.1mdv2009.0.i586.rpm
b00ca9e19282fcf71c3d76abb56b2196 2009.0/SRPMS/clamav-0.94.2-5.1mdv2009.0.src.rpm

Mandriva Linux 2009.0/X86_64:
44be18b884ca3d0b69e5e51afd07eca6 2009.0/x86_64/clamav-0.94.2-5.1mdv2009.0.x86_64.rpm
a7b2b3bb10bb921c9a1729f666d24ddf 2009.0/x86_64/clamav-db-0.94.2-5.1mdv2009.0.x86_64.rpm
e4c4df8e8ca4f7695ca70eed510f5bb4 2009.0/x86_64/clamav-milter-0.94.2-5.1mdv2009.0.x86_64.rpm
d41c03e799b515231078bd0bae91296e 2009.0/x86_64/clamd-0.94.2-5.1mdv2009.0.x86_64.rpm
417035e6244a49b0a1462ee27ef31562 2009.0/x86_64/lib64clamav5-0.94.2-5.1mdv2009.0.x86_64.rpm
a0bf8046d9de907030a8bfe6756d27a1 2009.0/x86_64/lib64clamav-devel-0.94.2-5.1mdv2009.0.x86_64.rpm
b00ca9e19282fcf71c3d76abb56b2196 2009.0/SRPMS/clamav-0.94.2-5.1mdv2009.0.src.rpm

Corporate 3.0:
d48eb70726cc553409bce0e08045d48c corporate/3.0/i586/clamav-0.94.2-4.1.C30mdk.i586.rpm
d781e584355ca33843743b10cbab6b0f corporate/3.0/i586/clamav-db-0.94.2-4.1.C30mdk.i586.rpm
bdc3f265ab484fd861d6387a6c7dab22 corporate/3.0/i586/clamav-milter-0.94.2-4.1.C30mdk.i586.rpm
568b14e5a45f49c027a4652da4c46030 corporate/3.0/i586/clamd-0.94.2-4.1.C30mdk.i586.rpm
0eae91fa32858b9d764b95cf64267755 corporate/3.0/i586/libclamav5-0.94.2-4.1.C30mdk.i586.rpm
b824200117b39c429a023a5b3df82a91 corporate/3.0/i586/libclamav-devel-0.94.2-4.1.C30mdk.i586.rpm
94a728a2dc9c9ebf058e5d5f19dce0c0 corporate/3.0/SRPMS/clamav-0.94.2-4.1.C30mdk.src.rpm

Corporate 3.0/X86_64:
dc151d5ea93ea02bb740057e7f72bc59 corporate/3.0/x86_64/clamav-0.94.2-4.1.C30mdk.x86_64.rpm
da7895038fc68d9e6b71333f2e7cf81e corporate/3.0/x86_64/clamav-db-0.94.2-4.1.C30mdk.x86_64.rpm
30943af3c0048965a75e842f7e7a1cc1 corporate/3.0/x86_64/clamav-milter-0.94.2-4.1.C30mdk.x86_64.rpm
56b7c5ad38199f61da3c1973ad7b4a8b corporate/3.0/x86_64/clamd-0.94.2-4.1.C30mdk.x86_64.rpm
a42c19e68345a21c0bedcb0a5ce3d8c7 corporate/3.0/x86_64/lib64clamav5-0.94.2-4.1.C30mdk.x86_64.rpm
edaa96f5ec3fd0a5305c800d04ec6a66 corporate/3.0/x86_64/lib64clamav-devel-0.94.2-4.1.C30mdk.x86_64.rpm
94a728a2dc9c9ebf058e5d5f19dce0c0 corporate/3.0/SRPMS/clamav-0.94.2-4.1.C30mdk.src.rpm

Corporate 4.0:
352dbe3a7c5072a33b06dfa9d1d47f79 corporate/4.0/i586/clamav-0.94.2-4.1.20060mlcs4.i586.rpm
71dad1bc81ba22cdbe9811e43b53eb78 corporate/4.0/i586/clamav-db-0.94.2-4.1.20060mlcs4.i586.rpm
ca6e18928def47896b89b0f0d72dca08 corporate/4.0/i586/clamav-milter-0.94.2-4.1.20060mlcs4.i586.rpm
9920edea586ea90296f57b601c9bdf7e corporate/4.0/i586/clamd-0.94.2-4.1.20060mlcs4.i586.rpm
72fe26aefc67de49a2ebe48d1f01bbfa corporate/4.0/i586/libclamav5-0.94.2-4.1.20060mlcs4.i586.rpm
db73242838bff1f6eec2eb14e31517d0 corporate/4.0/i586/libclamav-devel-0.94.2-4.1.20060mlcs4.i586.rpm
762cb5d2ba745b291c44336ebd01202d corporate/4.0/SRPMS/clamav-0.94.2-4.1.20060mlcs4.src.rpm

Corporate 4.0/X86_64:
948dc7ff829510cc9a771914578c020b corporate/4.0/x86_64/clamav-0.94.2-4.1.20060mlcs4.x86_64.rpm
7fdc45f60e098c116fcff11e7a17b2e0 corporate/4.0/x86_64/clamav-db-0.94.2-4.1.20060mlcs4.x86_64.rpm
cf8eecff2ffbd285dfe476b603499a93 corporate/4.0/x86_64/clamav-milter-0.94.2-4.1.20060mlcs4.x86_64.rpm
6e73a917707318616112fa65abc84480 corporate/4.0/x86_64/clamd-0.94.2-4.1.20060mlcs4.x86_64.rpm
b198d434dcad3d8f2c8cc8fdcccfed6b corporate/4.0/x86_64/lib64clamav5-0.94.2-4.1.20060mlcs4.x86_64.rpm
0435b58fe538c9888c07ff482db0e346 corporate/4.0/x86_64/lib64clamav-devel-0.94.2-4.1.20060mlcs4.x86_64.rpm
762cb5d2ba745b291c44336ebd01202d corporate/4.0/SRPMS/clamav-0.94.2-4.1.20060mlcs4.src.rpm
_______________________________________________________________________

To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com
_______________________________________________________________________

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iD8DBQFJwPOsmqjQ0CJFipgRAm0KAKCiAPzhVVSUTjFlZ3+FXvtcdLZc6ACg6q8f
Vi/hv7kS6ozQDa+6dLHVR3A=
=lOAG
-----END PGP SIGNATURE-----


------------=_1237393833-6173-3119
Content-Type: text/plain; name="message-footer.txt"
Content-Disposition: inline; filename="message-footer.txt"
Content-Transfer-Encoding: 8bit

To unsubscribe, send a email to sympa ( -at -) mandrivalinux.org
with this subject : unsubscribe security-announce
_______________________________________________________
Want to buy your Pack or Services from Mandriva?
Go to http://www.mandrivastore.com
Join the Club : http://www.mandrivaclub.com
_______________________________________________________

------------=_1237393833-6173-3119--