VulnerabilityModified
CVE-2023-24626
socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows local users to send a privileged SIGHUP signal to any PID, causing a denial of service or disruption of the target…
MEDIUM 6.5EPSS 0.54%
Does this matter?
Lower severity and a low EPSS score (0.54%). Track it; it rarely justifies an emergency change on its own.
Description
socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows local users to send a privileged SIGHUP signal to any PID, causing a denial of service or disruption of the target process.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
- EPSS
- 0.54% probability · 44th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-732
- Affected
- gnu/screen
- Source
- cve@mitre.org
References
- https://git.savannah.gnu.org/cgit/screen.git/patch/?id=e9ad41bfedb4537a6f0de20f00b27c7739f168f7Mailing List, Patch
- https://savannah.gnu.org/bugs/?63195Permissions Required
- https://www.exploit-db.com/exploits/51252Third Party Advisory, VDB Entry
- https://git.savannah.gnu.org/cgit/screen.git/patch/?id=e9ad41bfedb4537a6f0de20f00b27c7739f168f7Mailing List, Patch
- https://savannah.gnu.org/bugs/?63195Permissions Required
- https://security.netapp.com/advisory/ntap-20250509-0003/
- https://www.exploit-db.com/exploits/51252Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/51252Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.