GNU Screen Escape Sequence Integer Overflow Array Indexing Vulnerability

BID:9117

Info

GNU Screen Escape Sequence Integer Overflow Array Indexing Vulnerability

Bugtraq ID: 9117
Class: Boundary Condition Error
CVE: CVE-2003-0972
Remote: Yes
Local: Yes
Published: Nov 27 2003 12:00AM
Updated: Jul 12 2009 12:56AM
Credit: Discovery of this issue is credited to Timo Sirainen <[email protected]>.
Vulnerable: GNU screen 4.0.1
GNU screen 3.9.15
+ Mandriva Linux Mandrake 9.2
GNU screen 3.9.13
+ Conectiva Linux Enterprise Edition 1.0
+ Mandriva Linux Mandrake 9.1 ppc
+ Mandriva Linux Mandrake 9.1
GNU screen 3.9.11
- Caldera OpenLinux Server 3.1.1
- Caldera OpenLinux Workstation 3.1.1
- Debian Linux 2.2 sparc
- Debian Linux 2.2 powerpc
- Debian Linux 2.2 IA-32
- Debian Linux 2.2 arm
- Debian Linux 2.2 alpha
- Debian Linux 2.2 68k
- FreeBSD FreeBSD 4.5 -STABLE
- FreeBSD FreeBSD 4.5 -RELEASE
- FreeBSD FreeBSD 4.5
- FreeBSD FreeBSD 4.4 -STABLE
- FreeBSD FreeBSD 4.4 -RELENG
- FreeBSD FreeBSD 4.4
- FreeBSD FreeBSD 4.3 -STABLE
- FreeBSD FreeBSD 4.3 -RELENG
- FreeBSD FreeBSD 4.3 -RELEASE
- FreeBSD FreeBSD 4.3
- HP HP-UX 11.20
- HP HP-UX 11.11
- HP HP-UX 11.0
- HP HP-UX 10.20
+ MandrakeSoft Corporate Server 2.1 x86_64
+ MandrakeSoft Corporate Server 2.1
+ MandrakeSoft Multi Network Firewall 2.0
+ Mandriva Linux Mandrake 9.0
- Mandriva Linux Mandrake 8.2
- Mandriva Linux Mandrake 8.1 ia64
- Mandriva Linux Mandrake 8.1
- Mandriva Linux Mandrake 8.0 ppc
- Mandriva Linux Mandrake 8.0
- Mandriva Linux Mandrake 7.2
- NetBSD NetBSD 1.5.2
- NetBSD NetBSD 1.5.1
- NetBSD NetBSD 1.5
- OpenBSD OpenBSD 2.9
- OpenBSD OpenBSD 2.8
- OpenBSD OpenBSD 2.7
- OpenBSD OpenBSD 2.6
- OpenBSD OpenBSD 3.0
- Redhat Linux 7.2 ia64
- Redhat Linux 7.2 i386
- Redhat Linux 7.2 alpha
- Redhat Linux 7.1 ia64
- Redhat Linux 7.1 i386
- Redhat Linux 7.0 sparc
- Redhat Linux 7.0 i386
- Redhat Linux 7.0 alpha
- Redhat Linux 6.2 sparc
- Redhat Linux 6.2 i386
- Redhat Linux 6.2 alpha
- Slackware Linux 8.0
- Slackware Linux 7.1
- Sun Solaris 8_x86
- Sun Solaris 8_sparc
- Sun Solaris 7.0_x86
- Sun Solaris 7.0
- Sun Solaris 2.6_x86
- Sun Solaris 2.6
- SuSE Linux 7.1 sparc
- SuSE Linux 7.1 ppc
- SuSE Linux 7.1 alpha
- SuSE Linux 7.1
- SuSE Linux 7.0 sparc
- SuSE Linux 7.0 ppc
- SuSE Linux 7.0 i386
- SuSE Linux 7.0 alpha
- SuSE Linux 6.4 ppc
- SuSE Linux 6.4 i386
- SuSE Linux 6.4 alpha
GNU screen 3.9.10
- Caldera OpenLinux Server 3.1.1
- Caldera OpenLinux Workstation 3.1.1
- Debian Linux 2.2 sparc
- Debian Linux 2.2 powerpc
- Debian Linux 2.2 IA-32
- Debian Linux 2.2 arm
- Debian Linux 2.2 alpha
- Debian Linux 2.2 68k
- FreeBSD FreeBSD 4.5 -STABLE
- FreeBSD FreeBSD 4.5 -RELEASE
- FreeBSD FreeBSD 4.5
- FreeBSD FreeBSD 4.4 -STABLE
- FreeBSD FreeBSD 4.4 -RELENG
- FreeBSD FreeBSD 4.4
- FreeBSD FreeBSD 4.3 -STABLE
- FreeBSD FreeBSD 4.3 -RELENG
- FreeBSD FreeBSD 4.3 -RELEASE
- FreeBSD FreeBSD 4.3
- HP HP-UX 11.20
- HP HP-UX 11.11
- HP HP-UX 11.0
- HP HP-UX 10.20
- Mandriva Linux Mandrake 8.2
- Mandriva Linux Mandrake 8.1 ia64
- Mandriva Linux Mandrake 8.1
- Mandriva Linux Mandrake 8.0 ppc
- Mandriva Linux Mandrake 8.0
- Mandriva Linux Mandrake 7.2
- NetBSD NetBSD 1.5.2
- NetBSD NetBSD 1.5.1
- NetBSD NetBSD 1.5
- OpenBSD OpenBSD 2.9
- OpenBSD OpenBSD 2.8
- OpenBSD OpenBSD 2.7
- OpenBSD OpenBSD 2.6
- OpenBSD OpenBSD 3.0
- Redhat Linux 7.2 ia64
- Redhat Linux 7.2 i386
- Redhat Linux 7.2 alpha
- Redhat Linux 7.1 ia64
- Redhat Linux 7.1 i386
- Redhat Linux 7.0 sparc
- Redhat Linux 7.0 i386
- Redhat Linux 7.0 alpha
- Redhat Linux 6.2 sparc
- Redhat Linux 6.2 i386
- Redhat Linux 6.2 alpha
+ SCO OpenLinux Server 3.1.1
+ SCO OpenLinux Workstation 3.1.1
- Slackware Linux 8.0
- Slackware Linux 7.1
- Sun Solaris 8_x86
- Sun Solaris 8_sparc
- Sun Solaris 7.0_x86
- Sun Solaris 7.0
- Sun Solaris 2.6_x86
- Sun Solaris 2.6
- SuSE Linux 7.1 sparc
- SuSE Linux 7.1 ppc
- SuSE Linux 7.1 alpha
- SuSE Linux 7.1
- SuSE Linux 7.0 sparc
- SuSE Linux 7.0 ppc
- SuSE Linux 7.0 i386
- SuSE Linux 7.0 alpha
- SuSE Linux 6.4 ppc
- SuSE Linux 6.4 i386
- SuSE Linux 6.4 alpha
GNU screen 3.9.9
- Caldera OpenLinux Server 3.1.1
- Caldera OpenLinux Workstation 3.1.1
- Debian Linux 2.2 sparc
- Debian Linux 2.2 powerpc
- Debian Linux 2.2 IA-32
- Debian Linux 2.2 arm
- Debian Linux 2.2 alpha
- Debian Linux 2.2 68k
- FreeBSD FreeBSD 4.5 -STABLE
- FreeBSD FreeBSD 4.5 -RELEASE
- FreeBSD FreeBSD 4.5
- FreeBSD FreeBSD 4.4 -STABLE
- FreeBSD FreeBSD 4.4 -RELENG
- FreeBSD FreeBSD 4.4
- FreeBSD FreeBSD 4.3 -STABLE
- FreeBSD FreeBSD 4.3 -RELENG
- FreeBSD FreeBSD 4.3 -RELEASE
- FreeBSD FreeBSD 4.3
- HP HP-UX 11.20
- HP HP-UX 11.11
- HP HP-UX 11.0
- HP HP-UX 10.20
- Mandriva Linux Mandrake 8.2
- Mandriva Linux Mandrake 8.1 ia64
- Mandriva Linux Mandrake 8.1
- Mandriva Linux Mandrake 8.0 ppc
- Mandriva Linux Mandrake 8.0
- Mandriva Linux Mandrake 7.2
- NetBSD NetBSD 1.5.2
- NetBSD NetBSD 1.5.1
- NetBSD NetBSD 1.5
- OpenBSD OpenBSD 2.9
- OpenBSD OpenBSD 2.8
- OpenBSD OpenBSD 2.7
- OpenBSD OpenBSD 2.6
- OpenBSD OpenBSD 3.0
- Redhat Linux 7.2 ia64
- Redhat Linux 7.2 i386
- Redhat Linux 7.2 alpha
- Redhat Linux 7.1 ia64
- Redhat Linux 7.1 i386
- Redhat Linux 7.0 sparc
- Redhat Linux 7.0 i386
- Redhat Linux 7.0 alpha
- Redhat Linux 6.2 sparc
- Redhat Linux 6.2 i386
- Redhat Linux 6.2 alpha
- Slackware Linux 8.0
- Slackware Linux 7.1
- Sun Solaris 8_x86
- Sun Solaris 8_sparc
- Sun Solaris 7.0_x86
- Sun Solaris 7.0
- Sun Solaris 2.6_x86
- Sun Solaris 2.6
- SuSE Linux 7.1 sparc
- SuSE Linux 7.1 ppc
- SuSE Linux 7.1 alpha
- SuSE Linux 7.1
- SuSE Linux 7.0 sparc
- SuSE Linux 7.0 ppc
- SuSE Linux 7.0 i386
- SuSE Linux 7.0 alpha
- SuSE Linux 6.4 ppc
- SuSE Linux 6.4 i386
- SuSE Linux 6.4 alpha
GNU screen 3.9.8
- Caldera OpenLinux Server 3.1.1
- Caldera OpenLinux Workstation 3.1.1
- Debian Linux 2.2 sparc
- Debian Linux 2.2 powerpc
- Debian Linux 2.2 IA-32
- Debian Linux 2.2 arm
- Debian Linux 2.2 alpha
- Debian Linux 2.2 68k
- FreeBSD FreeBSD 4.5 -STABLE
- FreeBSD FreeBSD 4.5 -RELEASE
- FreeBSD FreeBSD 4.5
- FreeBSD FreeBSD 4.4 -STABLE
- FreeBSD FreeBSD 4.4 -RELENG
- FreeBSD FreeBSD 4.4
- FreeBSD FreeBSD 4.3 -STABLE
- FreeBSD FreeBSD 4.3 -RELENG
- FreeBSD FreeBSD 4.3 -RELEASE
- FreeBSD FreeBSD 4.3
- HP HP-UX 11.20
- HP HP-UX 11.11
- HP HP-UX 11.0
- HP HP-UX 10.20
- Mandriva Linux Mandrake 8.2
- Mandriva Linux Mandrake 8.1 ia64
- Mandriva Linux Mandrake 8.1
- Mandriva Linux Mandrake 8.0 ppc
- Mandriva Linux Mandrake 8.0
- Mandriva Linux Mandrake 7.2
- NetBSD NetBSD 1.5.2
- NetBSD NetBSD 1.5.1
- NetBSD NetBSD 1.5
- OpenBSD OpenBSD 2.9
- OpenBSD OpenBSD 2.8
- OpenBSD OpenBSD 2.7
- OpenBSD OpenBSD 2.6
- OpenBSD OpenBSD 3.0
- Redhat Linux 7.2 ia64
- Redhat Linux 7.2 i386
- Redhat Linux 7.2 alpha
- Redhat Linux 7.1 ia64
- Redhat Linux 7.1 i386
- Redhat Linux 7.0 sparc
- Redhat Linux 7.0 i386
- Redhat Linux 7.0 alpha
- Redhat Linux 6.2 sparc
- Redhat Linux 6.2 i386
- Redhat Linux 6.2 alpha
- Slackware Linux 8.0
- Slackware Linux 7.1
- Sun Solaris 8_x86
- Sun Solaris 8_sparc
- Sun Solaris 7.0_x86
- Sun Solaris 7.0
- Sun Solaris 2.6_x86
- Sun Solaris 2.6
- SuSE Linux 7.1 sparc
- SuSE Linux 7.1 ppc
- SuSE Linux 7.1 alpha
- SuSE Linux 7.1
- SuSE Linux 7.0 sparc
- SuSE Linux 7.0 ppc
- SuSE Linux 7.0 i386
- SuSE Linux 7.0 alpha
- SuSE Linux 6.4 ppc
- SuSE Linux 6.4 i386
- SuSE Linux 6.4 alpha
GNU screen 3.9.4
- Caldera OpenLinux Server 3.1.1
- Caldera OpenLinux Workstation 3.1.1
- Debian Linux 2.2 sparc
- Debian Linux 2.2 powerpc
- Debian Linux 2.2 IA-32
- Debian Linux 2.2 arm
- Debian Linux 2.2 alpha
- Debian Linux 2.2 68k
- FreeBSD FreeBSD 4.5 -STABLE
- FreeBSD FreeBSD 4.5 -RELEASE
- FreeBSD FreeBSD 4.5
- FreeBSD FreeBSD 4.4 -STABLE
- FreeBSD FreeBSD 4.4 -RELENG
- FreeBSD FreeBSD 4.4
- FreeBSD FreeBSD 4.3 -STABLE
- FreeBSD FreeBSD 4.3 -RELENG
- FreeBSD FreeBSD 4.3 -RELEASE
- FreeBSD FreeBSD 4.3
- HP HP-UX 11.20
- HP HP-UX 11.11
- HP HP-UX 11.0
- HP HP-UX 10.20
- Mandriva Linux Mandrake 8.2
- Mandriva Linux Mandrake 8.1 ia64
- Mandriva Linux Mandrake 8.1
- Mandriva Linux Mandrake 8.0 ppc
- Mandriva Linux Mandrake 8.0
- Mandriva Linux Mandrake 7.2
- NetBSD NetBSD 1.5.2
- NetBSD NetBSD 1.5.1
- NetBSD NetBSD 1.5
- OpenBSD OpenBSD 2.9
- OpenBSD OpenBSD 2.8
- OpenBSD OpenBSD 2.7
- OpenBSD OpenBSD 2.6
- OpenBSD OpenBSD 3.0
- Redhat Linux 7.2 ia64
- Redhat Linux 7.2 i386
- Redhat Linux 7.2 alpha
- Redhat Linux 7.1 ia64
- Redhat Linux 7.1 i386
- Redhat Linux 7.0 sparc
- Redhat Linux 7.0 i386
- Redhat Linux 7.0 alpha
- Redhat Linux 6.2 sparc
- Redhat Linux 6.2 i386
- Redhat Linux 6.2 alpha
- Slackware Linux 8.0
- Slackware Linux 7.1
- Sun Solaris 8_x86
- Sun Solaris 8_sparc
- Sun Solaris 7.0_x86
- Sun Solaris 7.0
- Sun Solaris 2.6_x86
- Sun Solaris 2.6
- SuSE Linux 7.1 sparc
- SuSE Linux 7.1 ppc
- SuSE Linux 7.1 alpha
- SuSE Linux 7.1
- SuSE Linux 7.0 sparc
- SuSE Linux 7.0 ppc
- SuSE Linux 7.0 i386
- SuSE Linux 7.0 alpha
- SuSE Linux 6.4 ppc
- SuSE Linux 6.4 i386
- SuSE Linux 6.4 alpha
Not Vulnerable:

Discussion

GNU Screen Escape Sequence Integer Overflow Array Indexing Vulnerability

GNU Screen is prone to a signed integer overflow vulnerability that may be triggered by including 2-gigabytes or more of semi-colons (;) or colones (:) in an escape sequence. This will cause an internal variable to wrap to a negative value, causing a size check to succeed when it should have failed. Further operations using this negative value may potentially cause memory to be corrupted with attacker-controlled data, potentially allowing for code execution.

This issue could be exploited locally to gain elevated privileges or in some cases remote exploitation may also be possible (though unlikely due to the amount of data required) since escape sequences could originate from a remote network session using SSH, telnet or another network client. Screen is usually installed with setgid utmp or setuid root permissions.

Exploit / POC

GNU Screen Escape Sequence Integer Overflow Array Indexing Vulnerability

Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] &lt;mailto:[email protected]&gt;.

Solution / Fix

GNU Screen Escape Sequence Integer Overflow Array Indexing Vulnerability

Solution:
SCO have released an advisory (CSSA-2004-011.0) and fixes to address this issue in OpenLinux 3.1.1 Server and Workstation. Please see referenced advisory for additional details regarding obtaining and applying appropriate fixes. Fixes are linked below.

OpenPKG has released a security advisory OpenPKG-SA-2003.050 to address this issue. Please see the referenced advisory for detailed information about obtaining fixes.

Mandrake has released an advisory and fixes to address this issue.

Debian has released security advisory DSA 408-1 to address this issue.

Conectiva has released security advisory CLSA-2004:805 to address this issue in CLEE 1.0. Conectiva also released advisory CLA-2004:809 for Conectiva Linux 8 and 9.


GNU screen 3.9.10

GNU screen 3.9.11

GNU screen 3.9.13

GNU screen 3.9.15

References

GNU Screen Escape Sequence Integer Overflow Array Indexing Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report