CVE-2023-24626: Medium severity suse screen vulnerability
socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows local users to send a privileged SIGHUP signal to any PID, causing a denial of service or disruption of the target process.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-24626?
CVE-2023-24626 is a vulnerability in GNU Screen through version 4.9.0 that allows local users to send a privileged SIGHUP signal to any PID, causing a denial of service or disruption of the target process.
How does CVE-2023-24626 affect GNU Screen?
CVE-2023-24626 affects GNU Screen through version 4.9.0 when it is installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD).
What is the severity of CVE-2023-24626?
CVE-2023-24626 has a severity rating of 6.5 (medium).
How can CVE-2023-24626 be exploited?
CVE-2023-24626 can be exploited by local users sending a privileged SIGHUP signal to any PID, causing a denial of service or disruption of the target process.
Can CVE-2023-24626 be fixed?
Yes, CVE-2023-24626 can be fixed by updating GNU Screen to a version beyond 4.9.0.