GNU Screen v.5.0.1 is released
Alex Naumov <[email protected]> Mon, 12 May 2025 22:36:32 +0200
| Newsgroups | gmane.comp.gnu.screen.devel,gmane.comp.gnu.screen.user |
|---|---|
| Message-ID | <CABPy6+wO_5F3JiWbUbeYwavqpuT9RoqTG1gNdcOnOUEc7bjAAQ@mail.gmail.com> |
--00000000000018a8f10634f64699 Content-Type: text/plain; charset="UTF-8" Hi everyone, I'm glad to announce the new release of GNU screen. Screen is a full-screen window manager that multiplexes a physical terminal between several processes, typically interactive shells. 5.0.1 is a security fix release. It includes only a few code fixes, types and security issues. It doesn't include any new features. - CVE-2025-46805: do NOT send signals with root privileges - CVE-2025-46804: avoid file existence test information leaks - CVE-2025-46803: apply safe PTY default mode of 0620 - CVE-2025-46802: prevent temporary 0666 mode on PTYs in attacher - CVE-2025-23395: reintroduce lf_secreopen() for logfile - buffer overflow due bad strncpy() - uninitialized variables warnings - typos - combining char handling that could lead to a segfault Release (official tarball) will be available soon for download: https://ftp.gnu.org/gnu/screen/ Please report any bugs or regressions. Thanks to everyone who contributed to this release. Cheers, Alex --00000000000018a8f10634f64699 Content-Type: text/html; charset="UTF-8" <div dir="ltr"><div dir="ltr"><div>Hi everyone,</div>I'm glad to announce the new release of GNU screen.<br><div><br> Screen is a full-screen window manager that multiplexes a physical terminal between several processes, typically interactive shells. <br><p>5.0.1 is a security fix release. It includes only a few code fixes, types and security issues. It doesn't include any new features. </p> <ul><li>CVE-2025-46805: do NOT send signals with root privileges </li><li>CVE-2025-46804: avoid file existence test information leaks </li><li>CVE-2025-46803: apply safe PTY default mode of 0620 </li><li>CVE-2025-46802: prevent temporary 0666 mode on PTYs in attacher </li><li>CVE-2025-23395: reintroduce lf_secreopen() for logfile </li><li>buffer overflow due bad strncpy() </li><li>uninitialized variables warnings </li><li>typos </li><li>combining char handling that could lead to a segfault </li></ul> <p> <br> Release (official tarball) will be available soon for download: <br> <a href="https://ftp.gnu.org/gnu/screen/">https://ftp.gnu.org/gnu/screen/</a> <br></p>Please report any bugs or regressions.<br> Thanks to everyone who contributed to this release. <br> <br> Cheers, <br> Alex </div></div><br></div> --00000000000018a8f10634f64699--