GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile permissions.
CVSS Details
- CVSS 3.0 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade screen | Aug 30, 2017 | Mar 20, 2017 |
| Debian | — | Upgrade screen | Jul 30, 2024 | Mar 20, 2017 |
| Oracle Solaris | — | Upgrade terminal/screen to version 4.5.1-0.175.3.20.0.4.0 on Solaris 11.3 | May 29, 2017 | Mar 20, 2017 |
| Suse | — | Upgrade screen | May 19, 2018 | Mar 20, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub