Integer signedness error in ansi.c for GNU screen 4.0.1 and earlier, and 3.9.15 and earlier, allows local users to execute arbitrary code via a large number of ";" (semicolon) characters in escape sequences, which leads to a buffer overflow.
A buffer overflow was found in the way GNU Screen before 4.8.0 treated the special escape OSC 49. Specially crafted output, or a special program, could corrupt memory and crash Screen or possibly have unspecified other impact.
GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile permissions.
DISPUTED GNU screen 4.0.3 allows local users to unlock the screen via a CTRL-C sequence at the password prompt. NOTE: multiple third parties report inability to reproduce this issue.
A security flaw was found in the screen utility in the way it used to create one particular temporary file. An attacker could use this flaw to perform a symlink attack.
References: https://bugs.launchpad.net/ubuntu/+source/screen/+bug/315993 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=521123
Buffer overflow in the Braille module for GNU screen 3.9.11, when HAVEBRAILLE is defined, allows local users to execute arbitrary code.
Multiple unspecified vulnerabilities in the "utf8 combining characters handling" (utf8handlecomb function in encoding.c) in screen before 4.0.3 allows user-assisted attackers to cause a denial of service (crash or hang) via certain UTF8 sequences.