GNU Screen v.5.0.1 is released

Alex Naumov <[email protected]> Mon, 12 May 2025 22:36:32 +0200
Newsgroups gmane.comp.gnu.screen.devel,gmane.comp.gnu.screen.user
Message-ID <CABPy6+wO_5F3JiWbUbeYwavqpuT9RoqTG1gNdcOnOUEc7bjAAQ@mail.gmail.com>
--00000000000018a8f10634f64699
Content-Type: text/plain; charset="UTF-8"

Hi everyone,
I'm glad to announce the new release of GNU screen.

Screen is a full-screen window manager that multiplexes a physical terminal
between several processes, typically interactive shells.

5.0.1 is a security fix release. It includes only a few code fixes, types
and security issues. It doesn't include any new features.

   - CVE-2025-46805: do NOT send signals with root privileges
   - CVE-2025-46804: avoid file existence test information leaks
   - CVE-2025-46803: apply safe PTY default mode of 0620
   - CVE-2025-46802: prevent temporary 0666 mode on PTYs in attacher
   - CVE-2025-23395: reintroduce lf_secreopen() for logfile
   - buffer overflow due bad strncpy()
   - uninitialized variables warnings
   - typos
   - combining char handling that could lead to a segfault


Release (official tarball) will be available soon for download:
https://ftp.gnu.org/gnu/screen/
Please report any bugs or regressions.
Thanks to everyone who contributed to this release.

Cheers,
Alex

--00000000000018a8f10634f64699
Content-Type: text/html; charset="UTF-8"

<div dir="ltr"><div dir="ltr"><div>Hi everyone,</div>I&#39;m glad to announce the new release of GNU screen.<br><div><br>
Screen is a full-screen window manager that multiplexes a physical 
terminal between several processes, typically interactive shells.
<br><p>5.0.1 is a security fix release. It includes only a few code fixes, 
types and security issues. It doesn&#39;t include any new features.
</p>
<ul><li>CVE-2025-46805: do NOT send signals with root privileges
</li><li>CVE-2025-46804: avoid file existence test information leaks
</li><li>CVE-2025-46803: apply safe PTY default mode of 0620
</li><li>CVE-2025-46802: prevent temporary 0666 mode on PTYs in attacher
</li><li>CVE-2025-23395: reintroduce lf_secreopen() for logfile
</li><li>buffer overflow due bad strncpy()
</li><li>uninitialized variables warnings
</li><li>typos
</li><li>combining char handling that could lead to a segfault
</li></ul>
<p>
<br>
Release (official tarball) will be available soon for download:
<br>
<a href="https://ftp.gnu.org/gnu/screen/">https://ftp.gnu.org/gnu/screen/</a>
<br></p>Please report any bugs or regressions.<br>
Thanks to everyone who contributed to this release.
<br>

<br>
Cheers,
<br>
Alex
</div></div><br></div>

--00000000000018a8f10634f64699--