ChangeLog for: 2025-05-13 20:36:47
a/exfatprogs-1.2.9-x86_64-1.txz: Upgraded.
a/intel-microcode-20250512-noarch-1.txz: Upgraded.
ap/screen-5.0.1-x86_64-1.txz: Upgraded.
This update fixes security issues:
fix bad strncpy() which can lead to a buffer overflow.
logfile - reintroduce lf_secreopen().
attacher.c - prevent temporary 0666 mode on PTYs.
default PTY mode - apply safe default mode of 0620.
avoid file existence test information leaks.
socket.c - don't send signals with root privileges.
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2025-23395
https://www.cve.org/CVERecord?id=CVE-2025-46802
https://www.cve.org/CVERecord?id=CVE-2025-46803
https://www.cve.org/CVERecord?id=CVE-2025-46804
https://www.cve.org/CVERecord?id=CVE-2025-46805
(* Security fix *)
l/harfbuzz-11.2.1-x86_64-1.txz: Upgraded.