vendor:
Screen
by:
IhaQueR@IRCnet
7.5
CVSS
HIGH
Format String Vulnerability
Unknown
CWE
Product Name: Screen
Affected Version From: 3.9.5 and prior
Affected Version To: 3.9.5 and prior
Patch Exists: NO
Related CWE: Unknown
CPE: a:gnu:screen
Platforms Tested:
Unknown
Format string vulnerabilities in ‘screen’
The 'screen' utility in versions 3.9.5 and prior has multiple format string vulnerabilities that can be exploited by local users to elevate their privileges. If 'screen' is setuid root, an attacker can alter the contents of the variable storing the user id.
Mitigation:
Update to a version of 'screen' that is not vulnerable. Disable setuid root if not required.