Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-46804

Опубликовано: 12 мая 2025
Источник: redhat
CVSS3: 3.3

Описание

A minor information leak when running Screen with setuid-root privileges allows unprivileged users to deduce information about a path that would otherwise not be available. Affected are older Screen versions, as well as version 5.0.0.

A flaw was found in Screen. It generates an error message that allows unprivileged users to deduce information about a path that should not be accessible.

Меры по смягчению последствий

No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6screenOut of support scope
Red Hat Enterprise Linux 7screenOut of support scope

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-497
https://bugzilla.redhat.com/show_bug.cgi?id=2364202screen: File Existence Tests via Socket Lookup Error Messages

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
24 дня назад

A minor information leak when running Screen with setuid-root privileges allows unprivileged users to deduce information about a path that would otherwise not be available. Affected are older Screen versions, as well as version 5.0.0.

CVSS3: 3.3
nvd
24 дня назад

A minor information leak when running Screen with setuid-root privileges allows unprivileged users to deduce information about a path that would otherwise not be available. Affected are older Screen versions, as well as version 5.0.0.

CVSS3: 3.3
debian
24 дня назад

A minor information leak when running Screen with setuid-root privileg ...

CVSS3: 3.3
github
24 дня назад

A minor information leak when running Screen with setuid-root privileges allosw unprivileged users to deduce information about a path that would otherwise not be available. Affected are older Screen versions, as well as version 5.0.0.

3.3 Low

CVSS3