Name
screen
Version
4.9.1
Type
library
Description
Multiplexing terminal manager
Licenses
GPL-3.0-or-later
PURL
-
CPE
cpe:2.3:*:gnu:screen:4.9.1:*:*:*:*:*:*:*
Other Versions#
Patches#
#
Title
Author
Resolve
1
fix CVE-2025-46805: socket.c - don't send signals with root
Axel Beckert <abe@debian.org>
CVE-2025-46805
2
fix CVE-2025-46802: attacher.c - prevent temporary 0666 mode
Matthias Gerstner <matthias.gerstner@suse.de>
CVE-2025-46802
3
fix CVE-2025-46804: avoid file existence test information
Matthias Gerstner <matthias.gerstner@suse.de>
CVE-2025-46804
4
Patch #4
Kai Kang <kai.kang@windriver.com>
5
Patch #5
Amadeusz Sławiński <amade@asmblr.net>
6
fix for multijob build
Jackie Huang <jackie.huang@windriver.com>
Vulnerabilities#
Name
Analysis
Description
Patched
Screen version 5.0.0 and older version 4 releases have a TOCTOU race potentially allowing to send SIGHUP, SIGCONT to privileged processes when installed setuid-root.
Patched
A minor information leak when running Screen with setuid-root privileges allows unprivileged users to deduce information about a path that would otherwise not be available.
Affected are older Screen versions, as well as version 5.0.0.
Patched
For a short time they PTY is set to mode 666, allowing any user on the system to connect to the screen session.