diff --git a/CVE-2020-27347.patch b/CVE-2020-27347.patch deleted file mode 100644 index fe335b307e14a748af736933a0d695761ad57045..0000000000000000000000000000000000000000 --- a/CVE-2020-27347.patch +++ /dev/null @@ -1,30 +0,0 @@ -From a868bacb46e3c900530bed47a1c6f85b0fbe701c Mon Sep 17 00:00:00 2001 -From: nicm -Date: Thu, 29 Oct 2020 16:33:01 +0000 -Subject: [PATCH] Do not write after the end of the array and overwrite the - stack when colon-separated SGR sequences contain empty arguments. Reported by - Sergey Nizovtsev. - ---- - input.c | 7 ++++++- - 1 file changed, 6 insertions(+), 1 deletion(-) - -diff --git a/input.c b/input.c -index 42a60c92a..c280c0d97 100644 ---- a/input.c -+++ b/input.c -@@ -1976,8 +1976,13 @@ input_csi_dispatch_sgr_colon(struct input_ctx *ictx, u_int i) - free(copy); - return; - } -- } else -+ } else { - n++; -+ if (n == nitems(p)) { -+ free(copy); -+ return; -+ } -+ } - log_debug("%s: %u = %d", __func__, n - 1, p[n - 1]); - } - free(copy); diff --git a/tmux-3.1.tar.gz b/tmux-3.1.tar.gz deleted file mode 100644 index 84822e0a40876d9dbce4f781032c35dd68188d49..0000000000000000000000000000000000000000 Binary files a/tmux-3.1.tar.gz and /dev/null differ diff --git a/tmux-3.2a.tar.gz b/tmux-3.2a.tar.gz new file mode 100644 index 0000000000000000000000000000000000000000..a526fb084c2d93f594b8a3f719443d9e09b6be87 Binary files /dev/null and b/tmux-3.2a.tar.gz differ diff --git a/tmux.spec b/tmux.spec index 16871e67752a2b3c1e3f30945abf83ddd402400b..9107562d0c6b9509baeb8595f35eeeb301224476 100644 --- a/tmux.spec +++ b/tmux.spec @@ -1,8 +1,8 @@ %global _hardened_build 1 Name: tmux -Version: 3.1 -Release: 2 +Version: 3.2a +Release: 1 Summary: A terminal multiplexer License: ISC and BSD @@ -10,7 +10,6 @@ URL: https://tmux.github.io/ Source0: https://github.com/%{name}/%{name}/releases/download/%{version}/%{name}-%{version}.tar.gz Source1: bash_completion_tmux.sh -Patch1: CVE-2020-27347.patch BuildRequires: gcc libevent-devel ncurses-devel libutempter-devel @@ -64,6 +63,9 @@ fi %{_mandir}/man1/%{name}.1.gz %changelog +* Fri Dec 3 2021 yangcheng - 3.2a-1 +- DESC:upgrade to 3.2a + * Sat Nov 28 2020 wangye - 3.1-2 - DESC:fix CVE