The ChangeLog at the [URL] mentions for 2.4.4 (not in the tree): - Fix CVE-2015-5186 Audit: log terminal emulator escape sequences handling I am not sure if this is fixed in 2.4.3-r1, and if not this report should be reassigned to security@.
commit 916ff46bd38dfac4aa50f3f946eb63194381a18c Author: Jason Zaman <perfinion@g.o> Date: Sun Jul 17 13:42:31 2016 sys-process/audit: stable for alpha amd64 hppa ppc x86 (bug 588734) Package-Manager: portage-2.2.28 commit dca8025bffc3288ab37975c413a35e1dadc5d0b2 Author: Jason Zaman <perfinion@g.o> Date: Sun Jul 17 13:26:59 2016 sys-process/audit: bump to 2.6.4 bug 588734 Package-Manager: portage-2.2.28 commit a93ad00d13b2ac267bbcc4421beb7eb9a79481bd Author: Jason Zaman <perfinion@g.o> Date: Sun Jul 17 13:22:05 2016 sys-process/audit: bump to 2.4.4 bug 588734 Package-Manager: portage-2.2.28
2.4.3-r1 does not have the fix Stabilization is in bug 577770 2.4.4 has no changes to the ebuild, so i stabilized it for exactly the same arches as 2.4.3-r1. 2.6.4 I updated to eapi6 and will stabilize later
(In reply to Jason Zaman from comment #2) > 2.4.3-r1 does not have the fix > Stabilization is in bug 577770 > > 2.4.4 has no changes to the ebuild, so i stabilized it for exactly the same > arches as 2.4.3-r1. 2.6.4 I updated to eapi6 and will stabilize later You did what now?
I reverted that stabilisation attempt. Don't we test stuff anymore? Meanwhile, 2.6.5 is out.
@maintainer(s), can we call for stabilization yet?
@ Arches, please test and mark stabe: =sys-process/audit-2.6.4
amd64 stable
x86 stable
arm stable
Stable on alpha.
sparc stable
ia64 stable
ppc stable
ppc64 stable
Stable for HPPA.
GLSA Vote: No @ Maintainer(s): Please cleanup <sys-process/audit-2.4.4 (probably <sys-process/audit-2.6.4 but security only require cleanup of <2.4.4).
tree is clean