diff options
author | Divya Chellam <divya.chellam@windriver.com> | 2025-05-30 17:22:09 +0530 |
---|---|---|
committer | Richard Purdie <richard.purdie@linuxfoundation.org> | 2025-07-09 12:02:02 +0100 |
commit | 3bfd7f820459aaf0b7738b1d4b1d2351c22f7c21 (patch) | |
tree | 4807343a6dca7905b7e5bd1bc516d8a008d7d6ed /documentation/migration-guides/migration-1.7.rst | |
parent | 372f1b5741a1774249495f09fba51c2623d8ed34 (diff) | |
download | poky-master-next.tar.gz |
screen: update 5.0.0 -> 5.0.1master-next
This includes CVE-fix for CVE-2025-46805, CVE-2025-46804,
CVE-2025-46803, CVE-2025-46802 and CVE-2025-23395.
Changelog:
=========
https://cgit.git.savannah.gnu.org/cgit/screen.git/tree/src/ChangeLog?h=v.5.0.1
* Fixes:
- CVE-2025-46805: do NOT send signals with root privileges
- CVE-2025-46804: avoid file existence test information leaks
- CVE-2025-46803: apply safe PTY default mode of 0620
- CVE-2025-46802: prevent temporary 0666 mode on PTYs in attacher
- CVE-2025-23395: reintroduce lf_secreopen() for logfile
- buffer overflow due bad strncpy()
- uninitialized variables warnings
- typos
- combining char handling that could lead to a segfault
(From OE-Core rev: f398ff9af626730e0e4e02eea22b8cfe1682f49c)
Signed-off-by: Divya Chellam <divya.chellam@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Diffstat (limited to 'documentation/migration-guides/migration-1.7.rst')
0 files changed, 0 insertions, 0 deletions