Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-id: <9F893C48-015F-4A88-92F0-A75B731F3ABB@me.com>
Date: Wed, 04 Oct 2017 11:28:38 -0400
From: Joel Esler <joel.esler@...com>
To: oss-security@...ts.openwall.com
Subject: Re: clamav: md5 collision based detection avoidance,
 Was: Out of bounds read and segfault in xar parser

> On Oct 3, 2017, at 2:54 PM, klondike <klondike@...cosoft.es> wrote:
> 
> There is also another fun issue with the way caching works (which is
> enabled by default) that allows avoiding detection by ClamAV.

I will ensure this is prioritized for a future release.


--
Joel Esler
Manager
Talos Group
http://www.talosintelligence.com

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.