SB2017030128 - Improper Privilege Management in screen (Alpine package)
Published: March 1, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Privilege Management (CVE-ID: CVE-2017-5618)
The vulnerability allows a local authenticated user to execute arbitrary code.
GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile permissions.
Remediation
Install update from vendor's website.