Bug 1258802 (CVE-2015-6806)

Summary: CVE-2015-6806 screen: Stack overflow due to deep recursion causing process freeze
Product: [Other] Security Response Reporter: Adam Mariš <amaris>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED WONTFIX QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: jrusnack, lnykryn, phracek
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: impact=low,public=20150807,reported=20150831,source=internet,cvss2=3.5/AV:N/AC:M/Au:S/C:N/I:N/A:P,rhel-5/screen=wontfix,rhel-6/screen=wontfix,rhel-7/screen=wontfix,fedora-all/screen=affected,cwe=CWE-121
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2015-11-05 04:04:12 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---
Bug Depends On: 1258806    
Bug Blocks: 1258805    

Description Adam Mariš 2015-09-01 10:24:33 UTC
A vulnerability was found in screen causing stack overflow which results in crashing the screen server process. After running malicious command inside screen, it will recursively call MScrollV to depth n/256. This is time consuming and will overflow the stack if 'n' is huge.

CVE assignment:

http://seclists.org/oss-sec/2015/q3/485

Upstream patch:

http://git.savannah.gnu.org/cgit/screen.git/commit/?id=c336a32a1dcd445e6b83827f83531d4c6414e2cd

Upstream report (contains reproducer):

https://savannah.gnu.org/bugs/?45713

Comment 1 Adam Mariš 2015-09-01 10:28:27 UTC
Created screen tracking bugs for this issue:

Affects: fedora-all [bug 1258806]

Comment 3 Petr Hracek 2015-12-21 09:14:53 UTC
Shall I fix the screen bug or close it as WONTFIX too?

Why is this bug closed as WONTFIX?

Comment 4 Adam Mariš 2015-12-21 09:58:45 UTC
(In reply to Petr Hracek from comment #3)
> Shall I fix the screen bug or close it as WONTFIX too?
> 
> Why is this bug closed as WONTFIX?

This issue is not planned to be fixed in RHEL due to Low security impact.