Re: Clamav security patch
[email protected] (Helge Oldach)
| Newsgroups | gmane.os.freebsd.devel.ports |
|---|---|
| Message-ID | <[email protected]> |
Kurt Jaeger wrote on Sun, 15 Mar 2026 14:20:41 +0100 (CET): > > Kurt Jaeger ([email protected]) wrote on Pi Day 2026 09:39:53 +0100 (CET): > > > > > It builds but packaging fails. I don't have time this weekend to look into > > > > > this further. > > > > > > > > @work > > > > > > done > > > > Kindly apply to clamav-lts as well (probably requires straight-forward update to 1.4.4). Thanks. > > What's the reason for having 1.4.4 besides 1.5.2 ? > > Is there really that much of a difference ? Vendor provides both feature (1.5.2) and LTS (1.4.4) releases. https://docs.clamav.net/faq/faq-eol.html It appears we a refollowing suit: In our terms, the feature release is security/clamav (updated yesterday to 1.5.2) and the LTS release is security/clamav-lts (still at 1.4.3). CVE-2026-20031 is fixed in both 1.5.2 and 1.4.4: https://blog.clamav.net/2026/03/clamav-152-and-144-security-patch.html I have no opinion about keeping or dropping clamav-lts but since we have it I suggest to fix CVE-2026-20031 likewise, which means 1.4.3 -> 1.4.4. Kind regards Helge