socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows local users to send a privileged SIGHUP signal to any PID, causing a denial of service or disruption of the target process.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Screen | Gnu | * | 4.9.0 (including) |
Screen | Ubuntu | bionic | * |
Screen | Ubuntu | esm-infra/bionic | * |
Screen | Ubuntu | esm-infra/xenial | * |
Screen | Ubuntu | kinetic | * |
Screen | Ubuntu | lunar | * |
Screen | Ubuntu | mantic | * |
Screen | Ubuntu | trusty | * |
Screen | Ubuntu | trusty/esm | * |
Screen | Ubuntu | upstream | * |
Screen | Ubuntu | xenial | * |