Screen: root exploit 4.5.0
Commit f86a374 (“screen.c: adding permissions check for the logfile name”, 2015-11-04)
The check opens the logfile with full root privileges. This allows us
to
truncate any file or create a root-owned file with any contents in any
directory and can be easily exploited to full root access in several
ways.
Affects:
screen 4.4.0 to and inclusive 4.5.0
References:
http://www.openwall.com/lists/oss-security/2017/01/24/10
http://savannah.gnu.org/bugs/?50142
(from redmine: issue id 6728, created on 2017-01-25, closed on 2017-03-02)
- Relations:
- child #6729 (closed)
- child #6730 (closed)