ALT-PU-2017-1266-1
Closed vulnerabilities
Modified: 2024-11-21
CVE-2007-3048
GNU screen 4.0.3 allows local users to unlock the screen via a CTRL-C sequence at the password prompt. NOTE: multiple third parties report inability to reproduce this issue
- 20070604 screen 4.0.3 local Authentication Bypass
- 20070604 screen 4.0.3 local Authentication Bypass
- 20070604 screen 4.0.3 local Authentication Bypass
- 20070604 screen 4.0.3 local Authentication Bypass
- 20070604 screen 4.0.3 local Authentication Bypass
- 20070604 screen 4.0.3 local Authentication Bypass
- 20070604 screen 4.0.3 local Authentication Bypass
- 20070604 screen 4.0.3 local Authentication Bypass
- screen-password-authentication-bypass(34693)
- screen-password-authentication-bypass(34693)
Modified: 2024-11-21
CVE-2009-1214
GNU screen 4.0.3 creates the /tmp/screen-exchange temporary file with world-readable permissions, which might allow local users to obtain sensitive session information.
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=521123
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=521123
- http://savannah.gnu.org/bugs/?25296
- http://savannah.gnu.org/bugs/?25296
- [oss-security] 20090325 CVE request -- zsh, XFree86-xfs/xorg-x11-xfs, screen
- [oss-security] 20090325 CVE request -- zsh, XFree86-xfs/xorg-x11-xfs, screen
- 34521
- 34521
- https://bugs.launchpad.net/ubuntu/+source/screen/+bug/315993
- https://bugs.launchpad.net/ubuntu/+source/screen/+bug/315993
- https://bugzilla.redhat.com/show_bug.cgi?id=492104
- https://bugzilla.redhat.com/show_bug.cgi?id=492104
- screen-screenexchange-info-disclosure(49886)
- screen-screenexchange-info-disclosure(49886)
Modified: 2024-11-21
CVE-2009-1215
Race condition in GNU screen 4.0.3 allows local users to create or overwrite arbitrary files via a symlink attack on the /tmp/screen-exchange temporary file.
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=521123
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=521123
- http://savannah.gnu.org/bugs/?25296
- http://savannah.gnu.org/bugs/?25296
- [oss-security] 20090325 CVE request -- zsh, XFree86-xfs/xorg-x11-xfs, screen
- [oss-security] 20090325 CVE request -- zsh, XFree86-xfs/xorg-x11-xfs, screen
- 34521
- 34521
- https://bugs.launchpad.net/ubuntu/+source/screen/+bug/315993
- https://bugs.launchpad.net/ubuntu/+source/screen/+bug/315993
- https://bugzilla.redhat.com/show_bug.cgi?id=492104
- https://bugzilla.redhat.com/show_bug.cgi?id=492104
- screen-screenexchange-symlink(49887)
- screen-screenexchange-symlink(49887)
Modified: 2024-11-21
CVE-2015-6806
The MScrollV function in ansi.c in GNU screen 4.3.1 and earlier does not properly limit recursion, which allows remote attackers to cause a denial of service (stack consumption) via an escape sequence with a large repeat count value.
- http://git.savannah.gnu.org/cgit/screen.git/commit/?id=b7484c224738247b510ed0d268cd577076958f1b
- http://git.savannah.gnu.org/cgit/screen.git/commit/?id=b7484c224738247b510ed0d268cd577076958f1b
- openSUSE-SU-2019:1485
- openSUSE-SU-2019:1485
- DSA-3352
- DSA-3352
- [oss-security] 20150901 CVE request: screen stack overflow (deep recursion)
- [oss-security] 20150901 CVE request: screen stack overflow (deep recursion)
- [oss-security] 20150904 Re: CVE request: screen stack overflow (deep recursion)
- [oss-security] 20150904 Re: CVE request: screen stack overflow (deep recursion)
- [oss-security] 20150903 AW: Re: CVE request: screen stack overflow (deep recursion)
- [oss-security] 20150903 AW: Re: CVE request: screen stack overflow (deep recursion)
- https://savannah.gnu.org/bugs/?45713
- https://savannah.gnu.org/bugs/?45713
- USN-3996-1
- USN-3996-1
Modified: 2024-11-21
CVE-2017-5618
GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile permissions.
- http://git.savannah.gnu.org/cgit/screen.git/patch/?id=1c6d2817926d30c9a7a97d99af7ac5de4a5845b8
- http://git.savannah.gnu.org/cgit/screen.git/patch/?id=1c6d2817926d30c9a7a97d99af7ac5de4a5845b8
- http://git.savannah.gnu.org/cgit/screen.git/tree/src/ChangeLog?h=v.4.5.1
- http://git.savannah.gnu.org/cgit/screen.git/tree/src/ChangeLog?h=v.4.5.1
- http://savannah.gnu.org/bugs/?50142
- http://savannah.gnu.org/bugs/?50142
- [oss-security] 20170129 Re: CVE request: GNU screen escalation
- [oss-security] 20170129 Re: CVE request: GNU screen escalation
- 95873
- 95873
- [screen-devel] 20170124 [bug #50142] root exploit 4.5.0
- [screen-devel] 20170124 [bug #50142] root exploit 4.5.0