Merge branch 'master' of git.clam.sourcefire.com:/var/lib/git/clamav-devel

pull/6/head
Kevin Lin 11 years ago
commit 4f4656626b
  1. 18
      NEWS
  2. 73
      README
  3. 57
      docs/clamdoc.tex
  4. 2
      docs/signatures.tex

18
NEWS

@ -56,5 +56,23 @@ Dave Simonson
Maarten Broekman
Christian Blichmann
--
REGARDING OPENSSL
In addition, as a special exception, the copyright holders give
permission to link the code of portions of this program with the
OpenSSL library under certain conditions as described in each
individual source file, and distribute linked combinations
including the two.
You must obey the GNU General Public License in all respects
for all of the code used other than OpenSSL. If you modify
file(s) with this exception, you may extend this exception to your
version of the file(s), but you are not obligated to do so. If you
do not wish to do so, delete this exception statement from your
version. If you delete this exception statement from all source
files in the program, then also delete it here.
--
The ClamAV team (http://www.clamav.net/team)

@ -5,6 +5,79 @@ here may not be available in binary packages.
0.98.2
------
Here are the new features and improvements in ClamAV 0.98.2:
- Support for common raw disk image formats using 512 byte sectors,
specifically GPT, APM, and MBR partitioning.
- Experimental support of OpenIOC files. ClamAV will now extract file
hashes from OpenIOC files residing in the signature database location,
and generate ClamAV hash signatures. ClamAV uses no other OpenIOC
features at this time. No OpenIOC files will be delivered through
freshclam. See openioc.org and iocbucket.com for additional information
about OpenIOC.
- All ClamAV sockets (clamd, freshclam, clamav-milter, clamdscan, clamdtop)
now support IPV6 addresses and configuration parameters.
- Use OpenSSL file hash functions for improved performance. OpenSSL
is now prerequisite software for ClamAV 0.98.2.
- Improved detection of malware scripts within image files. Issue reported
by Maarten Broekman.
- Change to circumvent possible denial of service when processing icons within
specially crafted PE files. Icon limits are now in place with corresponding
clamd and clamscan configuration parameters. This issue was reported by
Joxean Koret.
- Improvements to the fidelity of the ClamAV pattern matcher, an issue
reported by Christian Blichmann.
- Opt-in collection of statistics. Statistics collected are: sizes and MD5
hashes of files, PE file section counts and section MD5 hashes, and names
and counts of detected viruses. Enable statistics collection with the
--enable-stats clamscan flag or StatsEnabled clamd configuration
parameter.
- Improvements to ClamAV build process, unit tests, and platform support with
assistance and suggestions by Sebastian Andrzej Siewior, Scott Kitterman,
and Dave Simonson.
- Patch by Arkadiusz Miskiewicz to improve error handling in freshclam.
- ClamAV 0.98.2 also includes miscellaneous bug fixes and documentation
improvements.
Thanks to the following ClamAV community members for sending patches or reporting
bugs and issues that are addressed in ClamAV 0.98.2:
Sebastian Andrzej Siewior
Scott Kitterman
Joxean Koret
Arkadiusz Miskiewicz
Dave Simonson
Maarten Broekman
Christian Blichmann
--
REGARDING OPENSSL
In addition, as a special exception, the copyright holders give
permission to link the code of portions of this program with the
OpenSSL library under certain conditions as described in each
individual source file, and distribute linked combinations
including the two.
You must obey the GNU General Public License in all respects
for all of the code used other than OpenSSL. If you modify
file(s) with this exception, you may extend this exception to your
version of the file(s), but you are not obligated to do so. If you
do not wish to do so, delete this exception statement from your
version. If you delete this exception statement from all source
files in the program, then also delete it here.
0.98.1
------
ClamAV 0.98.1 provides improved support of Mac OS X platform, support for new file types, and

@ -1,5 +1,6 @@
% Clam AntiVirus: User Manual
%
% Copyright (C) 2014 Cisco Systems, Inc.
% Copyright (C) 2008-2013 Sourcefire, Inc.
% Copyright (C) 2002 - 2007 Tomasz Kojm <tkojm*clamav.net>
% Version 0.2x corrected by Dennis Leeuw <dleeuw*made-it.com>
@ -71,7 +72,7 @@
\vspace{3cm}
\begin{flushright}
\rule[-1ex]{8cm}{3pt}\\
\huge Clam AntiVirus 0.98.1\\
\huge Clam AntiVirus 0.98.2\\
\huge \emph{User Manual}\\
\end{flushright}
@ -83,7 +84,7 @@
\noindent
\begin{boxedminipage}[b]{\textwidth}
ClamAV User Manual,
\copyright \ 2007 - 2013 Sourcefire, Inc.
\copyright \ 2014 Cisco Systems, Inc.
Authors: Tomasz Kojm\\
This document is distributed under the terms of the GNU General
Public License v2.\\
@ -107,7 +108,7 @@
\vspace{0.3cm}
\noindent
\begin{boxedminipage}[b]{\textwidth}
ClamAV and Clam AntiVirus are trademarks of Sourcefire, Inc.
ClamAV and Clam AntiVirus are trademarks of Cisco Systems, Inc.
\end{boxedminipage}
\newpage
@ -149,6 +150,9 @@
\item PKG
\item HFS+ partition
\item HFSX partition
\item APM disk image
\item GPT disk image
\item MBR disk image
\item XAR
\item XZ
\item MS OLE2
@ -811,7 +815,7 @@ clamav-milter.conf not found
Software settings
-----------------
Version: 0.98.1
Version: 0.98.2
Optional features supported: MEMPOOL IPv6 AUTOIT_EA06 BZIP2 RAR JIT
Database information
@ -946,6 +950,9 @@ Engine flevel: 77, dconf: 77
\item PKG
\item HFS+ partition
\item HFSX partition
\item APM disk image
\item GPT disk image
\item MBR disk image
\item XAR
\item XZ
\item MS OLE2
@ -1733,38 +1740,41 @@ Verification OK.
\section{Core Team}
\begin{itemize}
\item Christoph Cordes \email{<ccordes*clamav.net>}, Germany\\
Role: virus database maintainer
\item Joel Esler \email{<jesler*sourcefire.com>}, USA\\
\item Joel Esler \email{<jesler*cisco.com>}, USA\\
Role: community manager
\item Tom Judge \email{<tjudge*sourcefire.com>}, USA\\
\item Erin Germ \email{<egerm*cisco.com>}, USA\\
Role: ClamAV quality engineering
\item Douglas Gastonguay-Goddard \email{<douggg*cisco.com>}, USA\\
Role: virus database maintainer
\item Tom Judge \email{<tomjudge*cisco.com>}, USA\\
Role: infrastucture developer
\item Steven Morgan \email{<smorgan*sourcefire.com>}, USA\\
Role: ClamAV developer
\item Steven Morgan \email{<stevmorg*cisco.com>}, USA\\
Role: ClamAV technical lead
\item Matthew Olney \email{<molney*sourcefire.com>}, USA\\
\item Matthew Olney \email{<molney*cisco.com>}, USA\\
Role: development manager
\item David Raynor \email{<draynor*sourcefire.com>}, USA\\
\item David Raynor \email{<draynor*cisco.com>}, USA\\
Role: ClamAV developer
\item Shawn Webb \email{<swebb*sourcefire.com>}, USA\\
\item Shawn Webb \email{<shawebb*sourcefire.com>}, USA\\
Role: ClamAV developer
\item Kevin Lin \email{<klin*sourcefire.com>}, USA\\
Role: ClamAV developer
\item Kevin Lin \email{<kevlin2*cisco.com>}, USA\\
Role: ClamAV developer
\item Dave Suffling \email{<dsuffling*sourcefire.com>}, Canada\\
Role: ClamAV developer
\item Dave Suffling \email{<dsufflin*cisco.com>}, Canada\\
Role: ClamAV developer
\item Samir Sapra \email{<ssapra*sourcefire.com>}, USA\\
Role: ClamAV developer
\item Samir Sapra \email{<ssapra*cisco.com>}, USA\\
Role: ClamAV developer
\item Alain Zidouemba \email{<azidouemba*sourcefire.com>}, USA\\
Role: virus database maintainer
\item Alain Zidouemba \email{<azidouem*cisco.com>}, USA\\
Role: manager, virus databases
\end{itemize}
@ -1774,6 +1784,9 @@ Verification OK.
\item aCaB \email{<acab*clamav.net>}, Italy\\
Role: virus database maintainer, coder
\item Christoph Cordes \email{<ccordes*clamav.net>}, Germany\\
Role: virus database maintainer
\item Mike Cathey \email{<mike*clamav.net>}, USA\\
Role: co-sysadmin

@ -450,6 +450,8 @@ Subsig1;Subsig2;...
\item \verb+EntryPoint+: Entry point offset (range in bytes; 0.96)
\item \verb+NumberOfSections+: Required number of sections in executable (range; 0.96)
\item \verb+Container:CL_TYPE_*+: File type of the container which stores the scanned file
\item \verb+IconGroup1+: Icon group name 1 from .idb signature Required engine functionality (range; 0.96)
\item \verb+IconGroup2+: Icon group name 2 from .idb signature Required engine functionality (range; 0.96)
\end{itemize}
Modifiers for subexpressions:
\begin{itemize}

Loading…
Cancel
Save