vendor:
Screen
by:
infodox
7,2
CVSS
HIGH
setuid screen v4.5.0 local root exploit
264
CWE
Product Name: Screen
Affected Version From: v4.5.0
Affected Version To: v4.5.0
Patch Exists: YES
Related CWE: N/A
CPE: a:gnu:screen:4.5.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2017
screenroot.sh
This exploit abuses ld.so.preload overwriting to get root. It creates a shell and library, then creates an /etc/ld.so.preload file and triggers it to get root.
Mitigation:
The best way to mitigate this vulnerability is to upgrade to the latest version of screen.