Virus Oversized.Zip detected

Stewart -


I am receiving the following SMTP error:

"550 Virus Oversized.Zip detected. Mail delivery avoided"


  • On-Premise Server + WebMail Installations: Version 6.0 > Current Version


This is due to the ClamAV engine of Atmail scanning a message attachment and the zip file compression ratio is too high. For example, zipping a large number of BMP files with high compression.

This feature is implemented in ClamAV to avoid a special crafted Zip file to loop on extraction causing a denial-of-service attempt.


To change the compression ratio simply edit: /usr/local/atmail/av/etc/clamd.conf

# If a file in an archive is compressed more than ArchiveMaxCompressionRatio
# times it will be marked as a virus (Oversized.ArchiveType, e.g. Oversized.Zip)
# Value of 0 disables the limit.
# Default: 250
ArchiveMaxCompressionRatio 0

Specify 0 to disable, or increase the ratio above the default 250, then restart the Atmail services.


