Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2025-46804

Published: May 14, 2025Last modified: May 17, 2025

Description

A minor information leak when running Screen with setuid-root privileges allosw unprivileged users to deduce information about a path that would otherwise not be available. Affected are older Screen versions, as well as version 5.0.0.

Severity score breakdown

ParameterValue
Base score3.3
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactNONE
Availability impactNONE
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSscreenFixed (4.9.1_git20250512-r0)
StreamscreenFixed (5.0.1-r0)

References

ON THIS PAGE