CVE-2017-5618: High severity GNU Screen vulnerability
Published Mar 20, 2017
·Updated
GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile permissions.
Affected Software
1 affected component
GNU Screen<=4.5.0
Remediation
Event History
Mar 20, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5618?
CVE-2017-5618 has a high severity score due to the potential for local users to gain root privileges.
2
How do I fix CVE-2017-5618?
To fix CVE-2017-5618, upgrade to GNU screen version 4.5.1 or later.
3
Who is affected by CVE-2017-5618?
Users of GNU screen versions prior to 4.5.1 are affected by CVE-2017-5618.
4
What kind of attacks does CVE-2017-5618 allow?
CVE-2017-5618 allows local users to modify arbitrary files, potentially leading to unauthorized privilege escalation.
5
Is CVE-2017-5618 a remote vulnerability?
No, CVE-2017-5618 is not a remote vulnerability; it requires local access to the system.