CVE-2017-5618
published 2017-03-20CVE-2017-5618: GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile…
PriorityP339high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
1.09%
61.4th percentile
GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile permissions.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | screen | < screen 4.5.0-3 (bookworm) | screen 4.5.0-3 (bookworm) |
| gnu | screen | <= 4.5.0 | — |
| gnu | screen | >= 0 < 4.5.0-3 | 4.5.0-3 |
| gnu | screen | >= 0 < 4.5.0-3 | 4.5.0-3 |
| gnu | screen | >= 0 < 4.5.0-3 | 4.5.0-3 |
| gnu | screen | >= 0 < 4.5.0-3 | 4.5.0-3 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qj7p-fvh6-8gg6: GNU screen before 4
ghsa_unreviewed·2022-05-13
CVE-2017-5618 [HIGH] CWE-863 GHSA-qj7p-fvh6-8gg6: GNU screen before 4
GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile permissions.
OSV
CVE-2017-5618: GNU screen before 4
osv·2017-03-20·CVSS 7.8
CVE-2017-5618 [HIGH] CVE-2017-5618: GNU screen before 4
GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile permissions.
Red Hat
screen: Privilege escalation via unsafe logfile handling
vendor_redhat·2017-01-24·CVSS 7.8
CVE-2017-5618 [HIGH] screen: Privilege escalation via unsafe logfile handling
screen: Privilege escalation via unsafe logfile handling
GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile permissions.
Package: screen (Red Hat Enterprise Linux 5) - Not affected
Package: screen (Red Hat Enterprise Linux 6) - Not affected
Package: screen (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2017-5618: screen - GNU screen before 4.5.1 allows local users to modify arbitrary files and consequ...
vendor_debian·2017·CVSS 7.8
CVE-2017-5618 [HIGH] CVE-2017-5618: screen - GNU screen before 4.5.1 allows local users to modify arbitrary files and consequ...
GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile permissions.
Scope: local
bookworm: resolved (fixed in 4.5.0-3)
bullseye: resolved (fixed in 4.5.0-3)
forky: resolved (fixed in 4.5.0-3)
sid: resolved (fixed in 4.5.0-3)
trixie: resolved (fixed in 4.5.0-3)
No detection rules found.
No public exploits indexed.
http://git.savannah.gnu.org/cgit/screen.git/patch/?id=1c6d2817926d30c9a7a97d99af7ac5de4a5845b8http://git.savannah.gnu.org/cgit/screen.git/tree/src/ChangeLog?h=v.4.5.1http://savannah.gnu.org/bugs/?50142http://www.openwall.com/lists/oss-security/2017/01/29/3http://www.securityfocus.com/bid/95873https://lists.gnu.org/archive/html/screen-devel/2017-01/msg00025.htmlhttp://git.savannah.gnu.org/cgit/screen.git/patch/?id=1c6d2817926d30c9a7a97d99af7ac5de4a5845b8http://git.savannah.gnu.org/cgit/screen.git/tree/src/ChangeLog?h=v.4.5.1http://savannah.gnu.org/bugs/?50142http://www.openwall.com/lists/oss-security/2017/01/29/3http://www.securityfocus.com/bid/95873https://lists.gnu.org/archive/html/screen-devel/2017-01/msg00025.html
2017-03-20
Published