cbcvebase.
CVE-2017-5618
published 2017-03-20

CVE-2017-5618: GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile…

high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile permissions.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianscreen< screen 4.5.0-3 (bookworm)screen 4.5.0-3 (bookworm)
gnuscreen<= 4.5.0
gnuscreen>= 0 < 4.5.0-34.5.0-3
gnuscreen>= 0 < 4.5.0-34.5.0-3
gnuscreen>= 0 < 4.5.0-34.5.0-3
gnuscreen>= 0 < 4.5.0-34.5.0-3

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH