SUSE-RU-2024:0184-1

Source
https://www.suse.com/support/update/announcement/2024/suse-ru-20240184-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-RU-2024:0184-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-RU-2024:0184-1
Upstream
  • CVE-2022-47016
Related
  • CVE-2022-47016
Published
2024-01-23T12:04:14Z
Modified
2025-05-02T04:10:57.696714Z
Summary
Recommended update for tmux
Details

This update for tmux fixes the following issues:

  • tmux: Null pointer dereference in window.c (bsc#1207393) (CVE-2022-47016)
  • add patch for compactibility with new ncurses fixes bsc#1210552
  • disable utf8proc (following upstreams not use it by default on non-macOS)
  • switch to screen-256color as default terminal to fix incompatibility with yast2-ruby-testsuite
  • update to 3.3a:
  • build with utf8proc enabled
  • refresh tmux-socket-path patch: restore ability to overwrite socket path using $TMUX_TMPDIR (bsc#1185572)
  • Drop pkgconfig(systemd) BuildRequires: there is no reason to pull in systemd into the build.
  • Use %tmpfiles_create instead of calling systemd-tmpfiles directly.
  • Replace systemdrequires with systemdordering: tmux is very well capable to run without systemd (and by using tmpfiles_create, the post script can also cope with the absence of if).
References

Affected packages

SUSE:Linux Enterprise Module for Package Hub 15 SP5 / tmux

Package

Name
tmux
Purl
pkg:rpm/suse/tmux&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.3a-150300.3.6.1

Ecosystem specific

{
    "binaries": [
        {
            "tmux": "3.3a-150300.3.6.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-RU-2024:0184-1.json"

openSUSE:Leap 15.5 / tmux

Package

Name
tmux
Purl
pkg:rpm/opensuse/tmux&distro=openSUSE%20Leap%2015.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.3a-150300.3.6.1

Ecosystem specific

{
    "binaries": [
        {
            "tmux": "3.3a-150300.3.6.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-RU-2024:0184-1.json"