Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ClamAV / clamd 0.100.0 #199

Closed
ghost235 opened this issue Jun 27, 2018 · 7 comments
Closed

ClamAV / clamd 0.100.0 #199

ghost235 opened this issue Jun 27, 2018 · 7 comments

Comments

@ghost235
Copy link

Hi,
is there an issue with Mailscanner 5.0.7 and ClamAV 0.100.0 ? I'am on debian 8.

Output from "/usr/lib/MailScanner/wrapper/clamav-wrapper /usr /tmp"
LibClamAV Error: yyerror(): /var/lib/clamav/antidebug_antivm.yar line 497 undefined identifier "pe"
LibClamAV Error: yyerror(): /var/lib/clamav/antidebug_antivm.yar line 512 undefined identifier "pe"
LibClamAV Error: yyerror(): /var/lib/clamav/antidebug_antivm.yar line 528 undefined identifier "pe"
LibClamAV Error: yyerror(): /var/lib/clamav/antidebug_antivm.yar line 544 undefined identifier "pe"
LibClamAV Error: yyerror(): /var/lib/clamav/antidebug_antivm.yar line 557 undefined identifier "pe"
LibClamAV Error: yyerror(): /var/lib/clamav/antidebug_antivm.yar line 603 undefined identifier "pe"
LibClamAV Error: yyerror(): /var/lib/clamav/antidebug_antivm.yar line 614 undefined identifier "pe"
LibClamAV Warning: cli_loadyara: failed to parse or load 7 yara rules from file /var/lib/clamav/antidebug_antivm.yar, successfully loaded 92 rules.
clamscan: yara_exec.c:177: yr_execute_code: Assertion `sp == 0' failed.
Aborted

In the mail.log I see:
MailScanner[27774]: ClamD Timed Out During PING Check!
MailScanner[17220]: Clamd::ERROR:: CLAM PING TIMED OUT! :: .
MailScanner[28459]: ClamD Timed Out During PING Check!
MailScanner[17100]: Clamd::ERROR:: CLAM PING TIMED OUT! :: .

@Skywalker-11
Copy link
Contributor

A quick google search leads to this
http://lists.mailscanner.info/pipermail/mailscanner/2014-May/101470.html

This happens just after FreshClam updated virus database and clamd loads new base. Loading virus database takes a while.

@ghost235
Copy link
Author

so you think something like http://lists.mailscanner.info/pipermail/mailscanner/2008-March/082465.html
will fix it ?

@Skywalker-11
Copy link
Contributor

From the statement I posted I guess it is just a temporary error. So it could help to increase the timeout but I never had the problem myself so no guarantees 😄.

@shawniverson
Copy link
Member

antidebug_antivm.yar isn't part of clamav itself, I believe, it is part of the clamav unofficial signatures, which appears to be what is throwing an error.

@shawniverson
Copy link
Member

@stefaweb
Copy link

stefaweb commented Jun 30, 2018

Greeu!

I updated before reading this.

Same problem here on Debian Jessie.

Also a problem with this:

WARNING: Ignoring deprecated option AllowSupplementaryGroups at line 11

@msapiro
Copy link
Contributor

msapiro commented Jun 30, 2018

As @shawniverson says, this is a known issue with the third party antidebug_antivm.yar signatures and clamav 0.100.0. It is not a MailScanner issue.

See the comment at extremeshok/clamav-unofficial-sigs#203 (comment) for a solution.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

5 participants