From de98f72736d8ee27c31226df46403b4e122733e2 Mon Sep 17 00:00:00 2001 From: Adolf Belka Date: Thu, 15 May 2025 18:25:25 +0200 Subject: [PATCH] screen: Update to version 5.0.1 - Update from version 5.0.0 to 5.0.1 - Update of rootfile - 5 CVE fixes included in this version - Changelog 5.0.1 Security fix CVE-2025-46805: do NOT send signals with root privileges CVE-2025-46804: avoid file existence test information leaks CVE-2025-46803: apply safe PTY default mode of 0620 CVE-2025-46802: prevent temporary 0666 mode on PTYs in attacher CVE-2025-23395: reintroduce lf_secreopen() for logfile buffer overflow due bad strncpy() uninitialized variables warnings typos combining char handling that could lead to a segfault Signed-off-by: Adolf Belka Signed-off-by: Michael Tremer --- config/rootfiles/common/screen | 3 +-- lfs/screen | 6 +++--- 2 files changed, 4 insertions(+), 5 deletions(-) diff --git a/config/rootfiles/common/screen b/config/rootfiles/common/screen index 3442bff2b..e8b72aaa2 100644 --- a/config/rootfiles/common/screen +++ b/config/rootfiles/common/screen @@ -1,7 +1,6 @@ etc/screenrc usr/bin/screen -usr/bin/screen-5.0.0 -#usr/share/info/screen.info +usr/bin/screen-5.0.1 #usr/share/man/man1/screen.1 #usr/share/screen #usr/share/screen/utf8encodings diff --git a/lfs/screen b/lfs/screen index 6388002cf..d1c0380fb 100644 --- a/lfs/screen +++ b/lfs/screen @@ -1,7 +1,7 @@ ############################################################################### # # # IPFire.org - A linux based firewall # -# Copyright (C) 2007-2024 IPFire Team # +# Copyright (C) 2007-2025 IPFire Team # # # # This program is free software: you can redistribute it and/or modify # # it under the terms of the GNU General Public License as published by # @@ -24,7 +24,7 @@ include Config -VER = 5.0.0 +VER = 5.0.1 THISAPP = screen-$(VER) DL_FILE = $(THISAPP).tar.gz @@ -40,7 +40,7 @@ objects = $(DL_FILE) $(DL_FILE) = $(DL_FROM)/$(DL_FILE) -$(DL_FILE)_BLAKE2 = 5ff218afc1692ae201776f759ff2217a51dcf02202e4ba5d12de50a768df83e0e2a7a3511a5f85a3b21362892f31a4fd90d6444918915165ae12a8c0c2b3af39 +$(DL_FILE)_BLAKE2 = f33f985bb9855a5335b72f93b3e8cf8fccddc7c18d3db3fd7493da2825b17002d798e6cf95d35fc39194eb6933018be96efa0b4f6aa4894657ab258f86002220 install : $(TARGET) -- 2.39.5