CVE-2025-23395

Screen 5.0.0 when it runs with setuid-root privileges does not drop privileges while operating on a user supplied path. This allows unprivileged users to create files in arbitrary locations with `root` ownership, the invoking user's (real) group ownership and file mode 0644. All data written to the Screen PTY will be logged into this file, allowing to escalate to root privileges
Configurations

No configuration.

History

28 May 2025, 15:01

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-26 16:15

Updated : 2025-05-28 15:01


NVD link : CVE-2025-23395

Mitre link : CVE-2025-23395

CVE.ORG link : CVE-2025-23395


JSON object : View

Products Affected

No product.

CWE
CWE-271

Privilege Dropping / Lowering Errors