Re: [oss-security] screen: Multiple Security Issues in Screen (mostly affecting release 5.0.0 and setuid-root installations)

2025-05-20 Thread Matthias Gerstner
Hello, On Fri, May 16, 2025 at 11:01:53AM -0400, Jan Schaumann wrote: > Matthias Gerstner wrote: > > we were surprised to find a local root exploit in > > the Screen 5.0.0 major version update affecting distributions that ship > > it as setuid-root (Arch Linux and NetBSD). > > I think it's usefu

[oss-security] CVE-2025-3908: OpenVPN 3 Linux v24.1 released

2025-05-20 Thread David Sommerseth
OpenVPN 3 Linux v24.1 was released 2025-05-19 which includes a fix for CVE-2025-3908. The OpenVPN 3 Linux v20 introduced a new command, openvpn3-admin init-config, to help getting an initial base configuration adopted to the currently running host. This command must be run as root. It was discov