Re: Clamav security patch
[email protected] (Helge Oldach)
| Newsgroups | gmane.os.freebsd.devel.ports |
|---|---|
| Message-ID | <[email protected]> |
Kurt Jaeger wrote on Sun, 15 Mar 2026 14:55:18 +0100 (CET): > Hi! > > > > What's the reason for having 1.4.4 besides 1.5.2 ? > > > > > > Is there really that much of a difference ? > > > > Vendor provides both feature (1.5.2) and LTS (1.4.4) releases. https://docs.clamav.net/faq/faq-eol.html > > > > It appears we a refollowing suit: In our terms, the feature release is security/clamav (updated yesterday to 1.5.2) and the LTS release is security/clamav-lts (still at 1.4.3). > > > > CVE-2026-20031 is fixed in both 1.5.2 and 1.4.4: https://blog.clamav.net/2026/03/clamav-152-and-144-security-patch.html > > > > I have no opinion about keeping or dropping clamav-lts but since we have it I suggest to fix CVE-2026-20031 likewise, which means 1.4.3 -> 1.4.4. > > Done. Thanks! Kind regards Helge