[Bug 1915205] Re: CVE-2020-9366

2021-02-09 Thread Bug Watch Updater
** Changed in: screen (Debian) Status: Unknown => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1915205 Title: CVE-2020-9366 To manage notifications about this bug go to: https:

Re: [Bug 1915205] Re: CVE-2020-9366

2021-02-09 Thread Steve Dodd
Ah, my apologies - hadn't spotted that it was a recently introduced bug! On Tue, 9 Feb 2021, 22:20 Steve Beattie, <1915...@bugs.launchpad.net> wrote: > Hello Steve, > > Thanks for reporting this issue. In this case, it is believed that the > vulnerability was introduced in screen 4.7.0 (via > > h

[Bug 1915205] Re: CVE-2020-9366

2021-02-09 Thread Steve Beattie
Hello Steve, Thanks for reporting this issue. In this case, it is believed that the vulnerability was introduced in screen 4.7.0 (via https://git.savannah.gnu.org/cgit/screen.git/commit/?id=c5db181b6e017cfccb8d7842ce140e59294d9f62 ), and then fixed in 4.8.0. Ubuntu 18.04 and older versions of scre

[Bug 1915205] Re: CVE-2020-9366

2021-02-09 Thread Axel Beckert
Actually this never made it into any LTS release as only 4.7.x versions were affected and 18.04 has a 4.6.x version and 20.04 has 4.8.0. ** Bug watch added: Debian Bug tracker #950896 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=950896 ** Also affects: screen (Debian) via https://bugs.

[Bug 1915205] Re: CVE-2020-9366

2021-02-09 Thread Axel Beckert
Marking as "fix release" as Ubuntu already has 4.8.0-1. ** Changed in: screen (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1915205 Title: CVE-2020-9366

[Bug 1915205] Re: CVE-2020-9366

2021-02-09 Thread Steve Beattie
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-9366 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1915205 Title: CVE-2020-9366 To manage notifications about this bug go to: https

[Bug 1915205] Re: CVE-2020-9366

2021-02-09 Thread Steve Dodd
Marking public as this is already known; might as well avoid dupes.. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1915205 Title: CVE-2020-9366 To manage notifications about this bug go to: https:/