Screen 5.0.0 when it runs with setuid-root privileges does not drop privileges while operating on a user supplied path. This allows unprivileged users to create files in arbitrary locations with `root` ownership, the invoking user's (real) group ownership and file mode 0644. All data written to the Screen PTY will be logged into this file, allowing to escalate to root privileges
                
            References
                    Configurations
                    No configuration.
History
                    28 May 2025, 15:01
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-05-26 16:15
Updated : 2025-05-28 15:01
NVD link : CVE-2025-23395
Mitre link : CVE-2025-23395
CVE.ORG link : CVE-2025-23395
JSON object : View
Products Affected
                No product.
CWE
                
                    
                        
                        CWE-271
                        
            Privilege Dropping / Lowering Errors
