Security Advisory

CVE-2025-23395

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-05-26 15:18:46
Last updated 2025-05-27 14:10:29
Assigner suse
CVSS score 7.8
State PUBLISHED

Description

Screen 5.0.0 when it runs with setuid-root privileges does not drop privileges while operating on a user supplied path. This allows unprivileged users to create files in arbitrary locations with `root` ownership, the invoking user's (real) group ownership and file mode 0644. All data written to the Screen PTY will be logged into this file, allowing to escalate to root privileges