-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 27 Feb 2021 01:52:03 +0100 Source: screen Architecture: source Version: 4.8.0-6 Distribution: unstable Urgency: medium Maintainer: Axel Beckert <abe@debian.org> Changed-By: Axel Beckert <abe@debian.org> Closes: 600246 Changes: screen (4.8.0-6) unstable; urgency=medium . * autopkgtest: Add a "sleep 1" before "Session is gone" check. Avoids a race condition on heavily loaded systems. * Replace 52fix_screen_utf8_nfd.patch with a patch by Michael Schröder and reenable it. (Closes: #600246 without reopening #677512; Culrpit was the same upstream commit as the one which caused CVE-2021-26937.) * Add additional autopkgtests, testing for regressions of #600246, #677512, #982435 (CVE-2021-26937) and some other regressions found in earlier patch propositions for CVE-2021-26937. * Update cause and impact description of CVE-2021-26937 in 4.8.0-4 with a shortened variant of the wording that is used by MITRE. Checksums-Sha1: abc39a074d5b8510665da2eb13b844f674a7f34a 2317 screen_4.8.0-6.dsc 14dfcdf7383bd24c1e95c6d267c32151fcca2693 50000 screen_4.8.0-6.debian.tar.xz a523c9332f792342cbbaaf84d54477e6f1ec6865 6707 screen_4.8.0-6_source.buildinfo Checksums-Sha256: 0ceddbed201114894bdb1911af1d4f96ac3dfbfc585ad604d4c041d437d39f98 2317 screen_4.8.0-6.dsc 7ef548223fd433bde8a29ecda1272bc06f461ac7d7fefa8bdb1b4df03f2d2e2b 50000 screen_4.8.0-6.debian.tar.xz 045f293832954fd37d9d730983ece2be9686946c609545795403c740cab6d036 6707 screen_4.8.0-6_source.buildinfo Files: 01746f64ba5ac25111f287d160d36be9 2317 misc standard screen_4.8.0-6.dsc da7d17bb52103c70ec504333f2b92347 50000 misc standard screen_4.8.0-6.debian.tar.xz 1e3f38f93a7e703a9f6c19965634c6d0 6707 misc standard screen_4.8.0-6_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERoyJeTtCmBnp12Ema+Zjx1o1yXUFAmA5mkAACgkQa+Zjx1o1 yXWlqg//cQhU/P1ETmKKxt68PXicncFfOtGYhdNkJS1s9stpbDdHygHBMJnuqSn+ e96Cncp0uRkh+AsCvR6sDC4bPUgdyDVsnjkbVDN0JuJoECB0A10qy+uQbtv8e297 jUazd2nv87fWGx9Ph4mri3YzWvgYzQvaZVkhimdGS41f5VNFFvxFY7d5COgeYeXe l8Yh7l0ioFUcn85yhNUquN+eYZkS9iafWv4QeyRlAYKfS+DEOhKY/YzZzGYUyGXn d942Xqdo98lE0Pv5tf03s/NvQuloKGx/YfIF0DOp/LajX+M9wt1OVps5xY+ZwVpE Kej60IsF4YWaPNhTtX+LW4BGMsAHCL2W0fbttO75RdGIImlB/gL25eZrJOQHyJpc Z6ACDO4SBVvHnKQ6MF81gEpFkYxG/zUhczNke0PZQkAgI81X3eGQzYdHZjYzZ9Xq fmiD+jqyyPYckAUTqbMf4kQMDIPRBtVh7eQcB5MAI7umqQEjD5tFosiD4j3uHByz LJ+Mhmeg1u2sTJwdRRv5whKhYx5TVsIuQUHHm/qkiNHa1Qhu6DiRip50zZixtRnC 3Rv2Qu2Yn3Iivx1D0n8oFr49QoHEBdaKyznwIERZteX9ugRa47HKMV+82IQDvRkb fkExphkSyBPdUK19ZH9zXcO6agLT8BIhRm60b8myqOTOjPq5e/A= =0yIB -----END PGP SIGNATURE-----