Hi, all,

I am pleased to announce the availability of Remind 06.00.01 at
https://dianne.skoll.ca/projects/remind/

This release adds one new feature (support for readline if you have
the readline library and headers installed) and one important bugfix.
The bug is potentially security-sensitive, so I recommend that
everyone upgrade.

If you cannot upgrade Remind, then I recommend recompiling your
existing version after editing the file remind-xxx/src/var.c and
removing the line that reads:

    DBufValue(&buf)[VAR_NAME_LEN] = 0;

Alternatively, you can try applying the patch attached to this email,
which keeps the assignment but puts a guard around it to ensure
there's no buffer overflow.

Direct download links:
Tar: https://dianne.skoll.ca/projects/remind/download/remind-06.00.01.tar.gz
GPG: https://dianne.skoll.ca/projects/remind/download/remind-06.00.01.tar.gz.sig
Git: https://git.skoll.ca/Skollsoft-Public/Remind

The git repo is password-protected to avoid AI scrapers; log in as
user "notabot" with password "notabot".  Alternatively, the mirror
https://salsa.debian.org/dskoll/remind does not require a login.

Complete release notes since the last release are below.

Regards,

Dianne.

CHANGES TO REMIND

* VERSION 6.0 Patch 1 - 2025-08-19

- NEW FEATURE: remind: Add readline support if input is taken from stdin
  (ie, "remind -").  This gives you full editing support if you run
  Remind interactively.

- BUG FIX: remind: Fix buffer overflow in DUMPVARS command.
  Thanks to Jochen Sprickerhof for helping me find this bug.

* VERSION 6.0 Patch 0 - 2025-08-18

Attachment: var.diff.gz
Description: application/gzip

Attachment: pgpEQAeo4860U.pgp
Description: OpenPGP digital signature

_______________________________________________
Remind-fans mailing list
[email protected]
https://dianne.skoll.ca/mailman/listinfo/remind-fans
Remind is at https://dianne.skoll.ca/projects/remind/

Reply via email to