Where
-Infinity
0

On 5/16/25 13:07, Eli Schwartz wrote: On 5/16/25 12:31 PM, Taylor R Campbell wrote: [...] (a) the same pkgsrc packages are available on, e.g., NetBSD 9.x (which is not EOL); and

(b) pkgsrc is used on platforms other than NetBSD, including macOS, SmartOS, and various Linux distributions (e.g., for unprivileged use on HPC clusters where it is more flexible and up-to-date than the Linux distribution's package manager).

That is why it would be more accurate for the report to say pkgsrc-2025Q1', not NetBSD 10.1'. I strongly dispute this. It should instead list both, as both are affected.

(Again, b is the same distinction as "Gentoo, but also portage-20250508, are both affected".)

-- Jacob

Date: Fri, 16 May 2025 11:34:29 -0400 From: Eli Schwartz <eschwartz () gentoo org>

On 5/16/25 11:01 AM, Jan Schaumann wrote: I think it's useful to clarify here that NetBSD does not ship with GNU screen(1) at all. NetBSD's third-party package manager pkgsrc[1] includes screen(1), allowing users to install additional software on top of the base OS.

That package as included in pkgsrc was installed setuid[2], but a NetBSD base installation does not include that package. (NetBSD happens to include tmux(1) in the base OS, but not screen(1).)

This distinction between a base OS and add-on software that is optionally available for users to choose tends to cause confusion for some people, so I figured it's worth noting. This is a nonsensical claim, but if I accept it as stated then I will counter-assert that zero (0) Linux distros are vulnerable as they don't preinstall screen in the base OS.

The definition of "the NetBSD base installation" is "nobody uses it". People use computing devices in order to run software on it. You cannot consider your OS in a bubble and go "well ackshually it's perfectly secure unless you use the builtin software to install official software, but we don't support that as a secure option". It is not nonsensical, and it is not the inconsequential pedantry you are suggesting. Please consider avoiding sarcastic disparagement when publicly discussing the factual matters of security reports.

The report says that NetBSD 10.1' is affected. This is not quite right, and it matters even if you set aside the fact that NetBSD 10.1 itself (which does ship tmux!) does not ship screen, because:

(a) the same pkgsrc packages are available on, e.g., NetBSD 9.x (which is not EOL); and

(b) pkgsrc is used on platforms other than NetBSD, including macOS, SmartOS, and various Linux distributions (e.g., for unprivileged use on HPC clusters where it is more flexible and up-to-date than the Linux distribution's package manager).

That is why it would be more accurate for the report to say pkgsrc-2025Q1', not NetBSD 10.1'.

All that said, I think any further discussion of this point -- and any other distributor-specific matters -- can reasonably be taken off-list to keep the thread focussed on the details of the screen vulnerabilities themselves.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203