store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Thu May 23, 2013 6:05 am

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 13 posts ] 
Author Message
 Post subject: Clamav 0.97.5 CL_EFORMAT: Bad format or broken data ERROR
Unread postPosted: Tue Jun 19, 2012 7:55 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1846
I've seen a few entries similar to the one below in the logs after updating to 0.97.5 the other day:

Code:
/var/spool/qscan/tmp/hostname.tld134010592679830512/image001.png: CL_EFORMAT: Bad format or broken data ERROR


Google shows a couple of recent posts on the subject in some clamav mailing lists but no actual info on the cause or what do so about it - if anything.

I don't suppose anyone here has any suggestions?

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
 Post subject: Re: Clamav 0.97.5 CL_EFORMAT: Bad format or broken data ERRO
Unread postPosted: Tue Jun 19, 2012 9:08 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7425
Location: earth
Have you tried turning it off and on again?!


Top
 Profile  
 
 Post subject: Re: Clamav 0.97.5 CL_EFORMAT: Bad format or broken data ERRO
Unread postPosted: Tue Jun 19, 2012 10:28 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1846
Is it meant to be plugged in when I do that? And what's with the drinks tray on this thing? Why do I need one on a server?

On the off-chance that you meant restart clamd...makes no difference.

Looking in more detail the log entries are all being triggered by a particular (legit) email containing this particular PNG. It isn't PNGs in general as I've tried sending tests with PNG attachments and all is well with those.

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
 Post subject: Re: Clamav 0.97.5 CL_EFORMAT: Bad format or broken data ERRO
Unread postPosted: Tue Jun 19, 2012 1:54 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
Does scanning the png from the filesystem generate this error? If so, can you send an strace (you may need to install the debug symbols btw)?

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Clamav 0.97.5 CL_EFORMAT: Bad format or broken data ERRO
Unread postPosted: Tue Jun 19, 2012 3:47 pm 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1846
That might be hard. It will be in a mime-encoded part of an incoming email which is being rejected by qmail-scanner.

I seem to remember someone telling me that a copy is stored somewhere even though I had thought they would not be. Can someone point me in the right direction please?

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
 Post subject: Re: Clamav 0.97.5 CL_EFORMAT: Bad format or broken data ERRO
Unread postPosted: Tue Jun 19, 2012 7:10 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
You could extract it from the email if you still have it, mimedecode or one of the other command line tools will do it.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Clamav 0.97.5 CL_EFORMAT: Bad format or broken data ERRO
Unread postPosted: Wed Jun 20, 2012 9:49 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1846
Well unfortunately I don't have the email - I can't see a way of obtaining it either :-(

I'm hoping that the other people also seeing this issue will have a bit more luck in being able to provide better debug data.

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
 Post subject: Re: Clamav 0.97.5 CL_EFORMAT: Bad format or broken data ERRO
Unread postPosted: Wed Jun 20, 2012 9:54 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1846
One of the threads about this says that the following test file also triggers the same issue:

/usr/src/clamav-0.97.5/test/.split/split.clam_IScab_int.exeaa

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
 Post subject: Re: Clamav 0.97.5 CL_EFORMAT: Bad format or broken data ERRO
Unread postPosted: Wed Jun 20, 2012 10:43 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
Its a bug in clamav. Being worked on, should have an update soon.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Clamav 0.97.5 CL_EFORMAT: Bad format or broken data ERRO
Unread postPosted: Wed Jun 20, 2012 3:59 pm 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1846
Interesting. Thanks for the update.

EDIT: Here's the link is anybody else is interested:
https://bugzilla.clamav.net/show_bug.cgi?id=5252

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
 Post subject: Re: Clamav 0.97.5 CL_EFORMAT: Bad format or broken data ERRO
Unread postPosted: Thu Jun 21, 2012 10:53 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7425
Location: earth
Backported into 0.95.5-7, try that out to see if it fixes it for you.


Top
 Profile  
 
 Post subject: Re: Clamav 0.97.5 CL_EFORMAT: Bad format or broken data ERRO
Unread postPosted: Thu Jun 21, 2012 5:00 pm 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1846
In progress....thanks.....

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
 Post subject: Re: Clamav 0.97.5 CL_EFORMAT: Bad format or broken data ERRO
Unread postPosted: Thu Jun 21, 2012 6:12 pm 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1846
Looking good. No error in almost an hour, which indicates all is well, I think. Thank you!

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 13 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group