Screen 5.0.0 when it runs with setuid-root privileges does not drop privileges while operating on a user supplied path. This allows unprivileged users to create files in arbitrary locations with `root` ownership, the invoking user's (real) group ownership and file mode 0644. All data written to the Screen PTY will be logged into this file, allowing to escalate to root privileges
References
Configurations
No configuration.
History
27 May 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References | () https://www.openwall.com/lists/oss-security/2025/05/12/1 - |
26 May 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-26 16:15
Updated : 2025-05-28 15:01
NVD link : CVE-2025-23395
Mitre link : CVE-2025-23395
CVE.ORG link : CVE-2025-23395
JSON object : View
Products Affected
No product.
CWE
CWE-271
Privilege Dropping / Lowering Errors