Record summary

CVE-2023-24626 has a selected CVSS score of 6.5 (medium); EIP currently links 1 catalogued exploit.

Description

socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows local users to send a privileged SIGHUP signal to any PID, causing a denial of service or disruption of the target process.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 12, 2025 · Source: CVE List

Proofs of concept

1

Catalogued exploits

ExploitDBGNU screen v4.9.0 - Privilege EscalationExploitDB exploitby Manuel AndreasNot analyzed1 file
ExploitDB

PoC details

References

5