AVG-2862 log

Package screen
Status Fixed
Severity High
Type multiple issues
Affected 5.0.0-2
Fixed 5.0.0-3
Current 5.0.1-2 [extra]
Ticket None
Created Tue May 13 18:58:50 2025
Issue Severity Remote Type Description
CVE-2025-46805 High No Denial of service
In socket.c lines 646 and 882 time-of-check/time-of-use (TOCTOU) race conditions exist with regards to sending signals to user supplied PIDs in setuid-root...
CVE-2025-46804 High No Privilege escalation
This is a minor information leak when running Screen with setuid-root privileges that is found in older Screen versions, as well as in version 5.0.0. The...
CVE-2025-46803 High No Access restriction bypass
In Screen version 5.0.0 the default mode of pseudo terminals (PTYs) allocated by Screen was changed from 0620 to 0622, thereby allowing anyone to write to...
CVE-2025-46802 High No Access restriction bypass
This issue is found in the Attach() function when the multiattach flag is set (i.e. Screen attempts to attach to a multi-user session). The function...
CVE-2025-23395 High No Privilege escalation
This issue affects Screen 5.0.0 when it runs with setuid-root privileges. The function logfile_reopen() does not drop privileges while operating on a user...
Date Advisory Package Type
13 May 2025 ASA-202505-1 screen multiple issues
References
https://www.openwall.com/lists/oss-security/2025/05/12/1
https://security.opensuse.org/2025/05/12/screen-security-issues.html