Bug 2364202 (CVE-2025-46804) - CVE-2025-46804 screen: File Existence Tests via Socket Lookup Error Messages
Summary: CVE-2025-46804 screen: File Existence Tests via Socket Lookup Error Messages
Keywords:
Status: NEW
Alias: CVE-2025-46804
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-05-05 20:15 UTC by OSIDB Bzimport
Modified: 2025-05-15 17:14 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-05-05 20:15:24 UTC
This is a minor information leak when running screen with setuid-root privileges that is found in older Screen versions, as well as in version 5.0.0.
The code in screen.c starting at line 849 inspects the resulting `SocketPath` with root privileges, and provides error messages that allow unprivileged users to deduce information about the path that would otherwise not be available.


Note You need to log in before you can comment on or make changes to this bug.