First published: Mon Mar 20 2017(Updated: )
GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile permissions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Screen | <=4.5.0 |
http://git.savannah.gnu.org/cgit/screen.git/patch/?id=1c6d2817926d30c9a7a97d99af7ac5de4a5845b8
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5618 has a high severity score due to the potential for local users to gain root privileges.
To fix CVE-2017-5618, upgrade to GNU screen version 4.5.1 or later.
Users of GNU screen versions prior to 4.5.1 are affected by CVE-2017-5618.
CVE-2017-5618 allows local users to modify arbitrary files, potentially leading to unauthorized privilege escalation.
No, CVE-2017-5618 is not a remote vulnerability; it requires local access to the system.