Published: 01/04/2009 Updated: 17/08/2017
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Race condition in GNU screen 4.0.3 allows local users to create or overwrite arbitrary files via a symlink attack on the /tmp/screen-exchange temporary file.

Vulnerability Trend

Affected Products

Vendor Product Versions
GnuGnu Screen4.0.3

Vendor Advisories

Debian Bug report logs - #521123 /tmp/screen-exchange still unsafe Package: screen; Maintainer for screen is Axel Beckert <abe@debianorg>; Source for screen is src:screen (PTS, buildd, popcon) Reported by: Kees Cook <kees@debianorg> Date: Wed, 25 Mar 2009 00:36:01 UTC Severity: normal Tags: security Found in vers ...

Github Repositories

