Red Hat Bugzilla – Bug 1416704
CVE-2017-5618 screen: Privilege escalation via unsafe logfile handling
Last modified: 2017-01-30 04:37:36 EST
A vulnerability was found in a way screen handles logfiles. A maliciously crafted logfile could allow the attacker to possibly elevate his privileges to those of root. References: https://lists.gnu.org/archive/html/screen-devel/2017-01/msg00025.html http://seclists.org/oss-sec/2017/q1/184
The vulnerable code is not present in screen as shipped in Red Hat Enterprise Linux versions 5, 6 and 7. Also, Red Hat Enterprise Linux versions 5, 6 and 7 are shipped with /usr/bin/screen SGID set to 'screen' group.
CVE assignment: http://seclists.org/oss-sec/2017/q1/224