Bug#982435: screen: CVE-2021-26937

2021-02-10 Thread Tavis Ormandy
On Wed, Feb 10, 2021 at 05:51:50PM +0100, Axel Beckert wrote: > > It though doesn't crash an unpatched screen. > Hey Axel, I tried to reply to your screen-devel post, but it's taking a while to subscribe! Here is the message I sent: On 2021-02-10, Axel Beckert wrote: > + else if (i < sizeof

Bug#982435: screen: CVE-2021-26937

2021-02-10 Thread Axel Beckert
Hi, Utkarsh Gupta wrote: > On Wed, Feb 10, 2021 at 6:56 PM Utkarsh Gupta wrote: > > I'll take care of fixing stretch and jessie and I am aware of all this > > since I was the one who got this CVE assigned! :D > > Somewhat related, I also got CVE-2021-27135 assigned for xterm. > I'll take care

Bug#982435: screen: CVE-2021-26937

2021-02-10 Thread Utkarsh Gupta
Hello, On Wed, Feb 10, 2021 at 6:56 PM Utkarsh Gupta wrote: > I'll take care of fixing stretch and jessie and I am aware of all this > since I was the one who got this CVE assigned! :D Somewhat related, I also got CVE-2021-27135 assigned for xterm. I'll take care of the updates when the patch

Bug#982435: screen: CVE-2021-26937

2021-02-10 Thread Utkarsh Gupta
On Wed, Feb 10, 2021 at 6:56 PM Utkarsh Gupta wrote: > I'll take care of fixing stretch and jessie and I am aware of all this > since I was the one who got this CVE assigned! :D Oh, I forgot to mention, I say this with my LTS and ELTS hat on!^ But in case if you want to work on the package

Bug#982435: screen: CVE-2021-26937

2021-02-10 Thread Utkarsh Gupta
Hi Axel, On Wed, Feb 10, 2021 at 5:17 PM Axel Beckert wrote: > Thanks for the heads up! Hadn't notice that upstream bug report > yesterday, but I do have it in my inbox. > > https://savannah.gnu.org/bugs/?60030 got locked down in the meanwhile > as it seems. > > Can you keep me in the loop wrt.

Processed: Re: Bug#982435: screen: CVE-2021-26937

2021-02-10 Thread Debian Bug Tracking System
Processing control commands: > tag -1 + confirmed Bug #982435 [src:screen] screen: CVE-2021-26937 Added tag(s) confirmed. > found -1 4.6.2-3 Bug #982435 [src:screen] screen: CVE-2021-26937 Marked as found in versions screen/4.6.2-3. > found -1 4.5.0-6 Bug #982435 [src:screen] screen:

Bug#982435: screen: CVE-2021-26937

2021-02-10 Thread Axel Beckert
Control: tag -1 + confirmed Control: found -1 4.6.2-3 Control: found -1 4.5.0-6 Control: found -1 4.2.1-3+deb8u1 Hi Salvatore, Salvatore Bonaccorso wrote: > The following vulnerability was published for screen, Thanks for the heads up! Hadn't notice that upstream bug report yesterday, but I do

Bug#982435: screen: CVE-2021-26937

2021-02-10 Thread Salvatore Bonaccorso
Source: screen Version: 4.8.0-3 Severity: grave Tags: security upstream Forwarded: https://lists.gnu.org/archive/html/screen-devel/2021-02/msg0.html X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for screen, filling it for now as RC