{"id":124670,"date":"2025-05-13T03:05:07","date_gmt":"2025-05-13T01:05:07","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-gnu-screen-pozvolyayushhaya-vypolnit-kod-s-pravami-root"},"modified":"2025-05-13T03:05:07","modified_gmt":"2025-05-13T01:05:07","slug":"uyazvimost-v-gnu-screen-pozvolyayushhaya-vypolnit-kod-s-pravami-root","status":"publish","type":"post","link":"https:\/\/prohoster.info\/pl\/blog\/news\/uyazvimost-v-gnu-screen-pozvolyayushhaya-vypolnit-kod-s-pravami-root","title":{"rendered":"Vulnerability in GNU screen allowing code execution with root privileges","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>In the console window manager (terminal multiplexer) GNU screen, which provides a multi-window interface in the console, 5 vulnerabilities have been identified. The most dangerous issue (CVE-2025-23395) allows gaining root privileges on the system. A fix has been included in today's release of screen 5.0.1.      <\/p>\n<p>The CVE-2025-23395 vulnerability is only present in the screen 5.0.0 branch, which is provided in Fedora Linux, Arch Linux, NetBSD, OpenBSD, and Alpine. In Debian, Ubuntu, RHEL (EPEL 9), Gentoo, FreeBSD, SUSE\/openSUSE, and OpenWrt, the screen 4.x branch continues to be distributed. Exploiting the vulnerability is possible in systems that install the screen executable with the setuid root flag, such as Arch Linux and NetBSD. In Fedora, the utility is installed with the setgid flag to obtain screen group privileges, allowing sockets to be placed in the system directory \/run\/screen, which limits the denial of service attack possibilities.       <\/p>\n<p>The vulnerability is caused by the fact that when run with root privileges, the logfile_reopen() function is executed before privilege drop, but processes data in the context of the directories of the current unprivileged user who started screen. Notably, the initial log opening is performed with a correct privilege drop, but upon reopening the log file, the privilege drop is not executed.    <\/p>\n<p>Dzi\u0119ki manipulacjom zwi\u0105zanym z w\u0142\u0105czeniem trybu rejestrowania sesji, u\u017cytkownik mo\u017ce uzyska\u0107 zapis danych do pliku z uprawnieniami roota, przy czym sam plik mo\u017ce by\u0107 zapisany w katalogu domowym u\u017cytkownika. Atak polega na usuni\u0119ciu utworzonego pliku z logiem i zast\u0105pieniu go dowi\u0105zaniem symbolicznym wskazuj\u0105cym na dowolny plik w systemie. Je\u015bli plik ju\u017c istnieje, dane z zawarto\u015bci\u0105 ekranu w sesji screen zostan\u0105 dodane do niego bez zmiany w\u0142a\u015bciciela. Je\u015bli plik nie istnieje \u2014 zostanie utworzony z uprawnieniami 0644, w\u0142a\u015bcicielem b\u0119dzie root, a grupa taka jak u bie\u017c\u0105cego u\u017cytkownika.    <\/p>\n<p>Algorytm ataku, kt\u00f3ry tworzy plik \/etc\/profile.d\/exploit.sh z komend\u0105 \u201echown $USER \/root\u201d:  <\/p>\n<ul>\n<li class=\"l\"> Creating a screen session with logging enabled: $ screen -Logfile $HOME\/screen.log\n<li class=\"l\"> Pressing the Ctrl-a-H key combination to enable logging.\n<li class=\"l\"> Deleting the log file and replacing it with a symbolic link, which will lead to the creation of the file \/etc\/profile.d\/exploit.sh: $ rm $HOME\/screen.log; ln -s \/etc\/profile.d\/exploit.sh $HOME\/screen.log\n<li class=\"l\"> Powr\u00f3t do sesji screen i wy\u015bwietlenie na ekranie danych, kt\u00f3re zostan\u0105 zapisane do pliku z logiem. $ echo -e \u201e\nchown $USER \/root;\u201d\n<li class=\"l\"> Po pod\u0142\u0105czeniu si\u0119 prawdziwego roota do systemu, uruchomi si\u0119 skrypt \/etc\/profile.d\/exploit.sh, kt\u00f3ry zmieni w\u0142a\u015bciciela katalogu \/root. $ ls -lhd \/root drwxr-x\u2014 5 user root 4.0K Dec 30 2020 .\n<li class=\"l\"> Podobnie mo\u017cna stworzy\u0107 pliki konfiguracyjne sudo lub doda\u0107 komendy na ko\u0144cu skrypt\u00f3w systemowych.    <\/ul>\n<p>Mniej niebezpieczne luki w ekranie:  <\/p>\n<ul>\n<li class=\"l\"> CVE-2025-46802 \u2014 przechwytywanie urz\u0105dzenia TTY w sesjach wielodost\u0119pnych (u\u017cytkownik mo\u017ce uzyska\u0107 uprawnienia crw-rw-rw- dla urz\u0105dzenia \/dev\/pts\/1). Problem wyst\u0119puje w wersjach screen 4.x i 5.x.\n<li class=\"l\"> CVE-2025-46803 \u2014 domy\u015blne ustawienie uprawnie\u0144 0622 dla urz\u0105dzenia PTY, umo\u017cliwiaj\u0105cych pisanie wszystkim u\u017cytkownikom. Problem wyst\u0119puje tylko w wersji screen 5.0.\n<li class=\"l\"> CVE-2025-46804 \u2014 wyciek informacji o istnieniu plik\u00f3w i katalog\u00f3w w zamkni\u0119tych katalogach (przy podawaniu katalogu dla gniazdka, u\u017cywaj\u0105c zmiennej \u015brodowiskowej SCREENDIR, narz\u0119dzie zwraca r\u00f3\u017cne komunikaty o b\u0142\u0119dach, kt\u00f3re sugeruj\u0105 istnienie plik\u00f3w i katalog\u00f3w o tej nazwie). Problem wyst\u0119puje w wersjach screen 4.x i 5.x.\n<li class=\"l\"> CVE-2025-46805 \u2014 stan wy\u015bcigu przy wysy\u0142aniu sygna\u0142\u00f3w SIGCONT i SIGHUP, prowadz\u0105cy do odmowy us\u0142ugi. Problem wyst\u0119puje w wersjach screen 4.x i 5.x.\n<li class=\"l\"> Niepoprawne u\u017cycie funkcji strncpy (zamiana strcpy na strncpy bez uwzgl\u0119dnienia r\u00f3\u017cnicy w obs\u0142udze zerowych symboli \u201e\n0\u201d), prowadz\u0105ce do awaryjnego zako\u0144czenia przy wykonywaniu specjalnie przygotowanych komend. Problem wyst\u0119puje tylko w wersji screen 5.0.  <\/ul>\n<p>Luki zosta\u0142y ujawnione w trakcie audytu bazy kodu GNU screen, przeprowadzonego przez zesp\u00f3\u0142 odpowiedzialny za bezpiecze\u0144stwo dystrybucji SUSE Linux. Informacje o lukach zosta\u0142y przes\u0142ane programistom ekranu 7 lutego, jednak w wyznaczonym czasie 90 dni nie byli w stanie przygotowa\u0107 poprawek dla wszystkich luk, w zwi\u0105zku z czym pracownicy SUSE musieli samodzielnie przygotowa\u0107 niekt\u00f3re poprawki. Wed\u0142ug badaczy przeprowadzaj\u0105cych audyt, obecni opiekunowie GNU screen nie orientuj\u0105 si\u0119 wystarczaj\u0105co dobrze w bazie kodu projektu i nie s\u0105 w stanie w pe\u0142ni zrozumie\u0107 zidentyfikowanych problem\u00f3w bezpiecze\u0144stwa.<br \/>\n<br \/>\u0179r\u00f3d\u0142o: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=63226\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043a\u043e\u043d\u0441\u043e\u043b\u044c\u043d\u043e\u043c \u043e\u043a\u043e\u043d\u043d\u043e\u043c \u043c\u0435\u043d\u0435\u0434\u0436\u0435\u0440\u0435 (\u043c\u0443\u043b\u044c\u0442\u0438\u043f\u043b\u0435\u043a\u0441\u043e\u0440\u0435 \u0442\u0435\u0440\u043c\u0438\u043d\u0430\u043b\u043e\u0432) GNU screen, \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u043c \u043c\u043d\u043e\u0433\u043e\u043e\u043a\u043e\u043d\u043d\u044b\u0439 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441 \u0432 \u043a\u043e\u043d\u0441\u043e\u043b\u0438, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 5 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439. \u041d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u043e\u043f\u0430\u0441\u043d\u0430\u044f \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 (CVE-2025-23395) \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u043f\u0440\u0430\u0432\u0430 root \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435. \u0418\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435 \u0432\u044b\u043a\u043b\u044e\u0447\u0435\u043d\u043e \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u0441\u0435\u0433\u043e\u0434\u043d\u044f\u0448\u043d\u0435\u0433\u043e \u0432\u044b\u043f\u0443\u0441\u043a\u0430 screen 5.0.1. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c CVE-2025-23395 \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0442\u043e\u043b\u044c\u043a\u043e \u0432 \u0432\u0435\u0442\u043a\u0435 screen 5.0.0, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0432 Fedora Linux, Arch Linux, NetBSD, OpenBSD \u0438 Alpine. \u0412 Debian, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-124670","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043a\u043e\u043d\u0441\u043e\u043b\u044c\u043d\u043e\u043c \u043e\u043a\u043e\u043d\u043d\u043e\u043c \u043c\u0435\u043d\u0435\u0434\u0436\u0435\u0440\u0435 (\u043c\u0443\u043b\u044c\u0442\u0438\u043f\u043b\u0435\u043a\u0441\u043e\u0440\u0435 \u0442\u0435\u0440\u043c\u0438\u043d\u0430\u043b\u043e\u0432) GNU screen, \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u043c \u043c\u043d\u043e\u0433\u043e\u043e\u043a\u043e\u043d\u043d\u044b\u0439 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441 \u0432 \u043a\u043e\u043d\u0441\u043e\u043b\u0438, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 5 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/pl\/blog\/news\/uyazvimost-v-gnu-screen-pozvolyayushhaya-vypolnit-kod-s-pravami-root\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"pl_PL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 GNU screen, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043a\u043e\u043d\u0441\u043e\u043b\u044c\u043d\u043e\u043c \u043e\u043a\u043e\u043d\u043d\u043e\u043c \u043c\u0435\u043d\u0435\u0434\u0436\u0435\u0440\u0435 (\u043c\u0443\u043b\u044c\u0442\u0438\u043f\u043b\u0435\u043a\u0441\u043e\u0440\u0435 \u0442\u0435\u0440\u043c\u0438\u043d\u0430\u043b\u043e\u0432) GNU screen, \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u043c \u043c\u043d\u043e\u0433\u043e\u043e\u043a\u043e\u043d\u043d\u044b\u0439 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441 \u0432 \u043a\u043e\u043d\u0441\u043e\u043b\u0438, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 5 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/pl\/blog\/news\/uyazvimost-v-gnu-screen-pozvolyayushhaya-vypolnit-kod-s-pravami-root\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2025-05-13T01:05:07+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2025-05-13T01:05:07+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Luka w GNU screen, umo\u017cliwiaj\u0105ca wykonywanie kodu z uprawnieniami roota | ProHoster","description":"W mened\u017cerze okien konsolowych (multiplexor terminali) GNU screen, kt\u00f3ry zapewnia interfejs wieloekranowy w konsoli, zidentyfikowano 5 luk w zabezpieczeniach.","canonical_url":"https:\/\/prohoster.info\/pl\/blog\/news\/uyazvimost-v-gnu-screen-pozvolyayushhaya-vypolnit-kod-s-pravami-root","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"pl_PL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 GNU screen, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root | ProHoster","og:description":"\u0412 \u043a\u043e\u043d\u0441\u043e\u043b\u044c\u043d\u043e\u043c \u043e\u043a\u043e\u043d\u043d\u043e\u043c \u043c\u0435\u043d\u0435\u0434\u0436\u0435\u0440\u0435 (\u043c\u0443\u043b\u044c\u0442\u0438\u043f\u043b\u0435\u043a\u0441\u043e\u0440\u0435 \u0442\u0435\u0440\u043c\u0438\u043d\u0430\u043b\u043e\u0432) GNU screen, \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u043c \u043c\u043d\u043e\u0433\u043e\u043e\u043a\u043e\u043d\u043d\u044b\u0439 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441 \u0432 \u043a\u043e\u043d\u0441\u043e\u043b\u0438, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 5 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439.","og:url":"https:\/\/prohoster.info\/pl\/blog\/news\/uyazvimost-v-gnu-screen-pozvolyayushhaya-vypolnit-kod-s-pravami-root","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2025-05-13T01:05:07+00:00","article:modified_time":"2025-05-13T01:05:07+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"124670","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 12:46:45","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 12:46:45","updated":"2026-01-23 12:46:45","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/posts\/124670","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/comments?post=124670"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/posts\/124670\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/media?parent=124670"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/categories?post=124670"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/tags?post=124670"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}