Debian 10168 Published by

A screen security update has been released for Debian GNU/Linux 8 Extended LTS to address an issue where remote attackers can cause a denial of service.



ELA-372-1 screen security update

Package screen
Version 4.2.1-3+deb8u2
Related CVEs CVE-2021-26937

encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact via a crafted UTF-8 character sequence.

NOTE: In order to bring this update to effect, you will need to restart your screen session(s).

For Debian 8 jessie, these problems have been fixed in version 4.2.1-3+deb8u2.

We recommend that you upgrade your screen packages.

Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/

  ELA-372-1 screen security update