Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-46802

Опубликовано: 26 мая 2025
Источник: debian

Описание

For a short time they PTY is set to mode 666, allowing any user on the system to connect to the screen session.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
screenfixed4.9.1-3package

Примечания

  • Fixed by: https://git.savannah.gnu.org/cgit/screen.git/commit/?id=049b26b22e197ba3be9c46e5c193032e01a4724a

  • https://www.openwall.com/lists/oss-security/2025/05/12/1

  • Has potential to break some reattach use cases, but the specific use case

  • was broken already before.

  • screen in Debian not installed setuid or setgid

Связанные уязвимости

CVSS3: 6
ubuntu
9 месяцев назад

For a short time they PTY is set to mode 666, allowing any user on the system to connect to the screen session.

CVSS3: 7.8
redhat
9 месяцев назад

For a short time they PTY is set to mode 666, allowing any user on the system to connect to the screen session.

CVSS3: 6
nvd
9 месяцев назад

For a short time they PTY is set to mode 666, allowing any user on the system to connect to the screen session.

suse-cvrf
7 месяцев назад

Security update for screen

suse-cvrf
8 месяцев назад

Security update for screen