X2Go Bug report logs - #1444
Firefox flags latest windows client download as virus or malware

Packages: windows, x2goclient; Maintainer for windows is (unknown); Maintainer for x2goclient is X2Go Developers <x2go-dev@lists.x2go.org>; Source for x2goclient is src:x2goclient.

Reported by: Chris Duffy <cadeon924@gmail.com>

Date: Mon, 2 Mar 2020 23:05:02 UTC

Severity: normal

Tags: not-a-bug

Done: Stefan Baur <X2Go-ML-1@baur-itcs.de>

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to x2go-dev@lists.x2go.org, X2Go Developers <x2go-dev@lists.x2go.org>, owner@bugs.x2go.org:
Bug#1444; Package x2goclient, windows. (Mon, 02 Mar 2020 23:05:02 GMT) (full text, mbox, link).


Acknowledgement sent to Chris Duffy <cadeon924@gmail.com>:
New Bug report received and forwarded. Copy sent to X2Go Developers <x2go-dev@lists.x2go.org>, owner@bugs.x2go.org.

Your message had a Version: pseudo-header with an invalid package version:

4.1.2.2, maybe others

please either use found or fixed to the control server with a correct version, or reply to this report indicating the correct version so the maintainer (or someone else) can correct it for you.

(Mon, 02 Mar 2020 23:05:02 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.x2go.org (full text, mbox, reply):

From: Chris Duffy <cadeon924@gmail.com>
To: submit@bugs.x2go.org
Subject: Firefox flags latest windows client download as virus or malware
Date: Mon, 2 Mar 2020 18:03:34 -0500
[Message part 1 (text/plain, inline)]
Package: x2goclient, windows
Version: 4.1.2.2, maybe others

Firefox flags x2goclient-4.1.2.2-2020.02.13-setup.exe as a virus. No
further information is provided.

I found links to a folder with earlier versions from this page:
https://wiki.x2go.org/doku.php/doc:installation:x2goclient

x2goclient-4.1.2.0-2018.06.22-setup.exe was not flagged, indicating that
the issue is in more recent builds.

Workaround: Downloaded and installing the older version from here:
https://code.x2go.org/releases/binary-win32/x2goclient/releases/4.1.2.0-2018.06.22/


[image: Capture.PNG]
[Message part 2 (text/html, inline)]
[Capture.PNG (image/png, inline)]

Information forwarded to x2go-dev@lists.x2go.org, X2Go Developers <x2go-dev@lists.x2go.org>, owner@bugs.x2go.org:
Bug#1444; Package x2goclient, windows. (Tue, 31 Mar 2020 12:50:02 GMT) (full text, mbox, link).


Acknowledgement sent to Stefan Baur <X2Go-ML-1@baur-itcs.de>:
Extra info received and forwarded to list. Copy sent to X2Go Developers <x2go-dev@lists.x2go.org>, owner@bugs.x2go.org. (Tue, 31 Mar 2020 12:50:02 GMT) (full text, mbox, link).


Message #10 received at 1444@bugs.x2go.org (full text, mbox, reply):

From: Stefan Baur <X2Go-ML-1@baur-itcs.de>
To: 1444@bugs.x2go.org, cadeon924@gmail.com
Subject: False Alert
Date: Tue, 31 Mar 2020 14:49:45 +0200
[Message part 1 (text/plain, inline)]
Control: close -1
Control: tag -1 not-a-bug

Closing this bug as it is a known false alert.  Whenever these
"smartscreen" filters (Chrome and Internet Explorer have them as well)
detect a Windows executable that isn't digitally signed (and our
detached GPG signatures don't count in that regard), and that hasn't
seen a large number of downloads, it will automatically flag it as
malicious.

If enough users report this to Mozilla/Google/Microsoft as a false
alert, a human will review the file and whitelist it.
Possibly this also happens over time, with a rising number of downloads
and/or the detection rates at virustotal.com not rising even after
several weeks.

I've just attempted a test download using the latest Firefox on a
Windows 10 machine, no such warning was issued any more.

-Stefan

-- 
BAUR-ITCS UG (haftungsbeschränkt)
Geschäftsführer: Stefan Baur
Eichenäckerweg 10, 89081 Ulm | Registergericht Ulm, HRB 724364
Fon/Fax 0731 40 34 66-36/-35 | USt-IdNr.: DE268653243

[signature.asc (application/pgp-signature, attachment)]

Marked Bug as done Request was from Stefan Baur <X2Go-ML-1@baur-itcs.de> to 1444-submit@bugs.x2go.org. (Tue, 31 Mar 2020 12:50:02 GMT) (full text, mbox, link).


Notification sent to Chris Duffy <cadeon924@gmail.com>:
Bug acknowledged by developer. (Tue, 31 Mar 2020 12:50:03 GMT) (full text, mbox, link).


Added tag(s) not-a-bug. Request was from Stefan Baur <X2Go-ML-1@baur-itcs.de> to 1444-submit@bugs.x2go.org. (Tue, 31 Mar 2020 12:50:03 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


X2Go Developers <owner@bugs.x2go.org>. Last modified: Tue Apr 7 16:49:39 2020; Machine Name: ymir.das-netzwerkteam.de

X2Go Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.