First published: Sun Jan 11 2009(Updated: )
A security flaw was found in the screen utility in the way it used to create one particular temporary file. An attacker could use this flaw to perform a symlink attack. References: <a href="https://bugs.launchpad.net/ubuntu/+source/screen/+bug/315993">https://bugs.launchpad.net/ubuntu/+source/screen/+bug/315993</a> <a href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=521123">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=521123</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU screen | =4.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1214 is classified as a moderate severity vulnerability.
To fix CVE-2009-1214, update GNU Screen to version 4.0.4 or later.
CVE-2009-1214 affects GNU Screen versions prior to 4.0.4.
CVE-2009-1214 may allow an attacker to perform a symlink attack.
CVE-2009-1214 is considered a local vulnerability, as it requires local access to exploit.