Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Bug]: Threat “EXP/Agent.EB.45” in libnextcloudsync.O.dylib of Mac client version 3.12.1 #6522

Closed
4 of 8 tasks
chadchr opened this issue Mar 8, 2024 · 3 comments
Closed
4 of 8 tasks

Comments

@chadchr
Copy link

chadchr commented Mar 8, 2024

⚠️ This issue respects the following points: ⚠️

Bug description

My Avira antivirus reported a threat of “EXP/Agent.EB.45” in libnextcloudsync.O.dylib when I tried installing Mac 64bit universal client version 3.12.1. I deleted that version and went back to 3.12.0 without any issues.

Steps to reproduce

  1. Install Mac client version 3.12.1

Expected behavior

I would expect my Antivirus not to report an issue.

Installation method

Community Web installer on a VPS or web space

Nextcloud Server version

26

Operating system

None

PHP engine version

None

Web server

None

Database engine version

None

Is this bug present after an update or on a fresh install?

None

Are you using the Nextcloud Server Encryption module?

None

What user-backends are you using?

  • Default user-backend (database)
  • LDAP/ Active Directory
  • SSO - SAML
  • Other

Configuration report

No response

List of activated Apps

No response

Nextcloud Signing status

No response

Nextcloud Logs

No response

Additional info

See https://www.reddit.com/r/NextCloud/comments/1b90v2x/threat_expagenteb45_in_libnextcloudsyncodylib_of/

@joshtrichards joshtrichards transferred this issue from nextcloud/server Mar 8, 2024
@pck1980
Copy link

pck1980 commented Mar 9, 2024

At VirusTotal, a total of 4 scanners detect a threat in the macOS pkg file:
https://www.virustotal.com/gui/file/6ac78e22c57c13884328f06deded69c75a157dad2f4349eb50b283b970bbf3fa

As this is likely a false positive, it would perhaps help to submit the suspected file to Avira for further analysis.

@pck1980
Copy link

pck1980 commented Mar 12, 2024

Avira on VirusTotal no longer flags the pkg as infected. From the four engines I mentioned above, only two remain.

@joshtrichards
Copy link
Member

Only one remains at this point.

I'm not going to install a random virus scanner to get more details. :-)

If someone uses the one in question, they can report it as a false positive (or maybe provide more details about what it has a problem with).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants