The release of the free antivirus package ClamAV 0.103.3 has been created, which offers the following changes:
- The file mirrors.dat has been renamed to freshclam.dat as ClamAV has switched to using a content delivery network (CDN) instead of a mirror network, and the specified dat file no longer contains information about mirrors. The freshclam.dat retains the UUID used in the User-Agent of ClamAV. The need for renaming is due to some users' scripts that were removing mirrors.dat in case of a FreshClam failure, but now this file contains an identifier, and losing it is unacceptable.
- Issues with low file scanning performance when the ENGINE_OPTIONS_FORCE_TO_DISK option is enabled have been resolved.
- Fixed a crash of the ClamDScan process when using the options "--fdpass --multiscan" along with the ExcludePath setting in the clamd configuration file.
- Resolved the issue of setting root as the owner of the mirrors.dat file instead of the user defined in the DatabaseOwner setting when starting clamav with root privileges.
- Ensured the HTTPUserAgent setting is disabled if clamav.net is used in DatabaseMirror to avoid accidental blocks.
- To enable detection of exploitation attempts of vulnerability CVE-2010-1205 (Heuristics.PNG.CVE-2010-1205), you now need to explicitly activate the ClamScan parameter "--alert-broken-media" or the "AlertBrokenMedia" setting, as the vulnerability has long been fixed everywhere.
- Fixed a ClamSubmit crash after the Cookie "__cfduid" was changed by Cloudflare.
Source: opennet.ru
