ELA-372-1 screen security update

denial of service

2021-02-26
Packagescreen
Version4.2.1-3+deb8u2
Related CVEs CVE-2021-26937

encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact via a crafted UTF-8 character sequence.

NOTE: In order to bring this update to effect, you will need to restart your screen session(s).

For Debian 8 jessie, these problems have been fixed in version 4.2.1-3+deb8u2.

We recommend that you upgrade your screen packages.

Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/