Vulnerability Name:

CVE-2017-5618 (CCN-123589)

Assigned:2017-03-20
Published:2017-03-20
Updated:2020-08-24
Summary:GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile permissions.
CVSS v3 Severity:7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
6.8 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-863
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2017-5618

Source: CONFIRM
Type: Patch, Third Party Advisory
http://git.savannah.gnu.org/cgit/screen.git/patch/?id=1c6d2817926d30c9a7a97d99af7ac5de4a5845b8

Source: CONFIRM
Type: Release Notes, Third Party Advisory
http://git.savannah.gnu.org/cgit/screen.git/tree/src/ChangeLog?h=v.4.5.1

Source: CONFIRM
Type: Third Party Advisory
http://savannah.gnu.org/bugs/?50142

Source: CCN
Type: oss-sec Mailing List, Sun, 29 Jan 2017 07:10:29 -0500
Re: CVE request: GNU screen escalation

Source: MLIST
Type: Exploit, Mailing List, Third Party Advisory
[oss-security] 20170129 Re: CVE request: GNU screen escalation

Source: BID
Type: Third Party Advisory, VDB Entry
95873

Source: CCN
Type: BID-95873
GNU Screen 'screen.c' Local Privilege Escalation Vulnerability

Source: XF
Type: UNKNOWN
gnu-screen-cve20175618-priv-esc(123589)

Source: MLIST
Type: Exploit, Third Party Advisory
[screen-devel] 20170124 [bug #50142] root exploit 4.5.0

Source: CCN
Type: GNU Screen Web site
GNU Screen

Vulnerable Configuration:Configuration 1:
  • cpe:/a:gnu:screen:*:*:*:*:*:*:*:* (Version <= 4.5.0)

  • Configuration CCN 1:
  • cpe:/a:gnu:screen:4.5.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20175618
    V
    CVE-2017-5618
    2022-08-07
    oval:org.opensuse.security:def:562
    P
    Security update for MozillaThunderbird (Important)
    2022-07-07
    oval:org.opensuse.security:def:3195
    P
    screen-4.6.2-5.3.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94825
    P
    screen-4.6.2-5.3.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:305
    P
    screen-4.6.2-5.3.1 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:268
    P
    perl-Mail-SpamAssassin-3.4.5-12.10.1 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:359
    P
    screen-4.6.2-5.3.1 on GA media (Moderate)
    2022-06-10
    oval:org.opensuse.security:def:1234
    P
    Security update for the Linux Kernel (Important)
    2022-05-16
    oval:org.opensuse.security:def:887
    P
    Security update for curl (Moderate)
    2022-05-13
    oval:org.opensuse.security:def:113429
    P
    screen-4.8.0-3.17 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:106830
    P
    screen-4.8.0-3.17 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:61651
    P
    screen-4.6.2-3.14 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:96771
    P
    screen-4.6.2-3.14 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71162
    P
    cron-4.2-4.45 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:103461
    P
    screen-4.6.2-3.14 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:89806
    P
    screen-4.6.2-3.14 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71392
    P
    screen-4.6.2-3.14 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:100656
    P
    (Important)
    2021-09-03
    oval:org.opensuse.security:def:47490
    P
    res-signingkeys-3.0.25-48.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47219
    P
    chrony-2.3-3.110 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48240
    P
    memcached-1.4.39-4.6.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47788
    P
    libsqlite3-0-3.8.10.2-8.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47544
    P
    MozillaFirefox-52.9.0esr-109.38.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47915
    P
    vsftpd-3.0.2-40.11.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47784
    P
    libsnmp30-32bit-5.7.3-6.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47118
    P
    pam_krb5-2.4.4-4.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47083
    P
    libtag1-1.9.1-1.218 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48017
    P
    ghostscript-9.27-23.28.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48082
    P
    libXpm4-3.5.11-5.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47342
    P
    libexif12-0.6.21-6.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47098
    P
    libxml2-2-2.9.4-27.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48209
    P
    libu2f-host0-1.1.6-3.5.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47704
    P
    libexempi3-2.2.1-5.7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47412
    P
    libsqlite3-0-3.8.10.2-8.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48311
    P
    squidGuard-1.4-30.6.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47850
    P
    perl-DBD-mysql-4.021-12.5.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47636
    P
    gtk2-data-2.24.31-7.11 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:46925
    P
    dhcp-4.3.3-9.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47946
    P
    apache-commons-beanutils-1.9.2-3.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47998
    P
    e2fsprogs-1.43.8-3.8.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47250
    P
    eog-3.20.4-7.7 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47084
    P
    libtasn1-3.7-11.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48144
    P
    libltdl7-2.4.2-17.4.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:101081
    P
    screen-4.6.2-5.3.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72064
    P
    screen-4.6.2-5.3.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62323
    P
    screen-4.6.2-5.3.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:69874
    P
    Security update for python-rsa (Important)
    2021-06-17
    oval:org.opensuse.security:def:46789
    P
    libzip2-0.11.1-9.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48949
    P
    libtag1-32bit-1.9.1-1.265 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46804
    P
    opie-2.4-724.65 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48709
    P
    ImageMagick-6.8.8.1-8.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46790
    P
    logrotate-3.8.7-3.21 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71098
    P
    screen-4.6.2-3.14 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48655
    P
    xorg-x11-server-7.6_1.18.3-57.34 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:61357
    P
    screen-4.6.2-3.14 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71049
    P
    libyaml-0-2-0.1.7-1.17 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:64462
    P
    Security update for fwupdate (Important)
    2021-04-08
    oval:org.opensuse.security:def:69979
    P
    Security update for wpa_supplicant (Important)
    2021-02-11
    oval:org.opensuse.security:def:67809
    P
    Security update for the Linux Kernel (Live Patch 19 for SLE 15) (Important)
    2021-02-10
    oval:org.opensuse.security:def:107322
    P
    screen-4.6.2-3.14 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:93943
    P
    screen-4.6.2-3.14 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71717
    P
    screen-4.6.2-3.14 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:61976
    P
    screen-4.6.2-3.14 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:49003
    P
    libFLAC++6-32bit-1.3.0-11.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:73314
    P
    screen on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67709
    P
    libopus0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73196
    P
    libpainter0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49274
    P
    logrotate on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66623
    P
    screen on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64375
    P
    libpython2_7-1_0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49328
    P
    screen on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66531
    P
    libsoup-2_4-1 on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.precise:def:20175618000
    V
    CVE-2017-5618 on Ubuntu 12.04 LTS (precise) - medium.
    2017-03-20
    oval:com.ubuntu.xenial:def:201756180000000
    V
    CVE-2017-5618 on Ubuntu 16.04 LTS (xenial) - medium.
    2017-03-20
    oval:com.ubuntu.trusty:def:20175618000
    V
    CVE-2017-5618 on Ubuntu 14.04 LTS (trusty) - medium.
    2017-03-20
    oval:com.ubuntu.xenial:def:20175618000
    V
    CVE-2017-5618 on Ubuntu 16.04 LTS (xenial) - medium.
    2017-03-20
    BACK
    gnu screen *
    gnu screen 4.5.0