Hi GNU Screen team, During a security review of GNU Screen, I have identified a set of three distinct bugs:
1. A Local Privilege Escalation (LPE) via an ACL bypass (CWE-863). 2. An Arbitrary File Read vulnerability. 3. An Arbitrary File Write / Append vulnerability via symlink bypasses (CWE-59/CWE-73). Since the GNU Savannah bug tracker and this mailing list are public, I do not want to disclose the full advisories and Proof-of-Concept scripts here to prevent abuse. Could the current maintainers please reply to me directly or provide a PGP key / private email address where I can securely send the full vulnerability reports and PoC ? Best regards, Rapido =)
