Gnu Screen vulnerabilities
9 known vulnerabilities affecting gnu/screen.
Total CVEs
9
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH2MEDIUM3LOW1
Vulnerabilities
Page 1 of 1
CVE-2023-24626MEDIUMCVSS 6.5PoC≤ 4.9.02023-04-08
CVE-2023-24626 [MEDIUM] CWE-732 CVE-2023-24626: socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such
socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows local users to send a privileged SIGHUP signal to any PID, causing a denial of service or disruption of the target process.
nvd
CVE-2021-26937CRITICALCVSS 9.8≤ 4.8.02021-02-09
CVE-2021-26937 [CRITICAL] CWE-88 CVE-2021-26937: encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid
encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact via a crafted UTF-8 character sequence.
nvd
CVE-2020-9366CRITICALCVSS 9.8fixed in 4.8.02020-02-24
CVE-2020-9366 [CRITICAL] CWE-787 CVE-2020-9366: A buffer overflow was found in the way GNU Screen before 4.8.0 treated the special escape OSC 49. Sp
A buffer overflow was found in the way GNU Screen before 4.8.0 treated the special escape OSC 49. Specially crafted output, or a special program, could corrupt memory and crash Screen or possibly have unspecified other impact.
nvd
CVE-2017-5618HIGHCVSS 7.8≤ 4.5.02017-03-20
CVE-2017-5618 [HIGH] CWE-863 CVE-2017-5618: GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root priv
GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile permissions.
nvd
CVE-2009-1214MEDIUMCVSS 4.9v4.0.32009-04-01
CVE-2009-1214 [MEDIUM] CWE-264 CVE-2009-1214: GNU screen 4.0.3 creates the /tmp/screen-exchange temporary file with world-readable permissions, wh
GNU screen 4.0.3 creates the /tmp/screen-exchange temporary file with world-readable permissions, which might allow local users to obtain sensitive session information.
nvd
CVE-2007-3048HIGHCVSS 7.2PoCv4.0.32007-06-05
CVE-2007-3048 [HIGH] CVE-2007-3048: GNU screen 4.0.3 allows local users to unlock the screen via a CTRL-C sequence at the password promp
GNU screen 4.0.3 allows local users to unlock the screen via a CTRL-C sequence at the password prompt. NOTE: multiple third parties report inability to reproduce this issue
nvd
CVE-2006-4573LOWCVSS 2.6≤ 4.0.22006-10-24
CVE-2006-4573 [LOW] CVE-2006-4573: Multiple unspecified vulnerabilities in the "utf8 combining characters handling" (utf8_handle_comb f
Multiple unspecified vulnerabilities in the "utf8 combining characters handling" (utf8_handle_comb function in encoding.c) in screen before 4.0.3 allows user-assisted attackers to cause a denial of service (crash or hang) via certain UTF8 sequences.
nvd
CVE-2003-0972CRITICALCVSS 10.0v3.9.4v3.9.8+6 more2003-12-15
CVE-2003-0972 [CRITICAL] CVE-2003-0972: Integer signedness error in ansi.c for GNU screen 4.0.1 and earlier, and 3.9.15 and earlier, allows
Integer signedness error in ansi.c for GNU screen 4.0.1 and earlier, and 3.9.15 and earlier, allows local users to execute arbitrary code via a large number of ";" (semicolon) characters in escape sequences, which leads to a buffer overflow.
nvd
CVE-2002-1602MEDIUMCVSS 4.6PoCv3.9.4v3.9.8+3 more2002-04-23
CVE-2002-1602 [MEDIUM] CVE-2002-1602: Buffer overflow in the Braille module for GNU screen 3.9.11, when HAVE_BRAILLE is defined, allows lo
Buffer overflow in the Braille module for GNU screen 3.9.11, when HAVE_BRAILLE is defined, allows local users to execute arbitrary code.
nvd