vendor:
screen
by:
Rembrandt
7.2
CVSS
HIGH
Local Authentication Bypass
287
CWE
Product Name: screen
Affected Version From: screen <= 4.0.3
Affected Version To: screen <= 4.0.3
Patch Exists: YES
Related CWE: CVE-2007-3048
CPE: a:gnu:screen:4.0.3
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: OpenBSD, OpenSuSE
2007
screen <= 4.0.3 Local Authentication Bypass
screen, on some operating systems, is vulnerable to a local terminal screen lock authentication bypass that may allow physically proximate attackers to gain access to the system. This issue has been confirmed on OpenBSD with screen 4.0.3 on x86/amd64. The underlying vulnerability may be related to 3rd party authentication such as PAM. This issue was tested on OpenSuSE with screen 4.0.2 and was not vulnerable.
Mitigation:
Tobias Ulmer has committed a patch to the screen codeline that will prevent this issue from occurring.