[Pkg-clamav-devel] Debian ClamAV and bug report #1080962

Sebastian Andrzej Siewior sebastian at breakpoint.cc
Fri Oct 11 20:19:08 BST 2024


On 2024-10-10 16:21:29 [-0400], Reid, Andrew C.E. (Fed) wrote:
> 
>   Hi again Sebastian --
Hi,

>   So I do have a further question, my expectation at this point
> is that a fixed package will appear in the repos, and the CVEs will
> show as fixed on the relevant Debian security pages.
> 
>   I haven't seen that yet, do you know how long that usually
> takes?  Or are my expectations wrong, and there's another 
> channel where things happen?

What happend as of today is that the clamav packages was accepted by the
release team. If you check
	https://release.debian.org/proposed-updates/stable.html

and search for "clamav" you will find it in the "Processed" area. The
two CVEs are referenced but are still red for Bookworm.
If you add the "bookworm-proposed-updates" suite then you are able to
update the clamav package (and all other from the Processed category).

The CVE gets updated during the point release. At this point, everything
from proposed-updates (and security archive) gets integrated into the
stable suite.

>   Thanks again for your engagement and help!

You are welcome.

>   				-- A.

Sebastian



More information about the Pkg-clamav-devel mailing list