Hi GNU Screen team,
During a security review of GNU Screen, I have identified a set of three
distinct bugs:

1. A Local Privilege Escalation (LPE) via an ACL bypass (CWE-863).
2. An Arbitrary File Read vulnerability.
3. An Arbitrary File Write / Append vulnerability via symlink bypasses
(CWE-59/CWE-73).

Since the GNU Savannah bug tracker and this mailing list are public, I do
not want to disclose the full advisories and Proof-of-Concept scripts here
to prevent abuse. Could the current maintainers please reply to me directly
or provide a PGP key / private email address where I can securely send the
full vulnerability reports and PoC ?

Best regards, Rapido =)

Reply via email to