Bug 13975

Summary: [CVE 21] screen 4.9.0 CVEs CVE-2023-24626 EXPLOIT https://www.exploit-db.com/download/51252 found
Product: [ROSA-based products] ROSA Fresh Reporter: Yury <y.tumanov>
Component: System (kernel, glibc, systemd, bash, PAM...)Assignee: ROSA Linux Bugs <bugs>
Status: VERIFIED FIXED QA Contact: ROSA Linux Bugs <bugs>
Severity: blocker    
Priority: Highest CC: a.proklov, pastordidi, s.matveev, v.potapov, y.tumanov
Version: AllFlags: v.potapov: qa_verified+
y.tumanov: secteam_verified+
a.proklov: published+
Target Milestone: 2021.1 Fresh R12   
Hardware: All   
OS: Linux   
URL: CVE-2023-24626 https://www.exploit-db.com/download/51252
Whiteboard:
Platform: 2021.1 ROSA Vulnerability identifier:
RPM Package: ISO-related:
Bad POT generating: Upstream:

Description Yury 2023-10-20 15:17:28 MSK
screen	4.9.0	CVE-2023-24626	socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows local users to send a privileged SIGHUP signal to any PID, causing a denial of service or disruption of the target process.	6,5	MEDIUM			NVD-CWE-noinfo			Не найден	https://nvd.nist.gov/vuln/detail/CVE-2023-24626	https://www.exploit-db.com/download/51252	Linux
Comment 1 Svyatoslav Matveev 2023-10-22 19:41:41 MSK
********** QA ADVISORY **********

Закрыто патчем.

*** screen
**  4.9.0 release +1

https://abf.io/build_lists/4760203
https://abf.io/build_lists/4760202
https://abf.io/build_lists/4760204
https://abf.io/build_lists/4760206
https://abf.io/build_lists/4760205
Comment 2 Dmitry Postnikov 2023-10-22 22:58:16 MSK
*******************************
Обновление отправлено в Тестинг
Comment 3 Vladimir Potapov 2023-10-24 12:56:00 MSK
screen-4.9.0-2
https://abf.io/build_lists/4760203
https://abf.io/build_lists/4760202
https://abf.io/build_lists/4760204
https://abf.io/build_lists/4760206
https://abf.io/build_lists/4760205
********************************* Advisory **************************
Critical CVE fix
*********************************************************************
QA Verified
Comment 4 Yury 2023-10-27 20:18:29 MSK
secteam_verified