CVE-2009-1214: Medium severity GNU Screen vulnerability
A security flaw was found in the screen utility in the way it used to create one particular temporary file. An attacker could use this flaw to perform a symlink attack.
References: https://bugs.launchpad.net/ubuntu/+source/screen/+bug/315993 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=521123
Other sources
GNU screen 4.0.3 creates the /tmp/screen-exchange temporary file with world-readable permissions, which might allow local users to obtain sensitive session information.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1214?
CVE-2009-1214 is classified as a moderate severity vulnerability.
How do I fix CVE-2009-1214?
To fix CVE-2009-1214, update GNU Screen to version 4.0.4 or later.
What systems are affected by CVE-2009-1214?
CVE-2009-1214 affects GNU Screen versions prior to 4.0.4.
What type of attack is possible with CVE-2009-1214?
CVE-2009-1214 may allow an attacker to perform a symlink attack.
Is CVE-2009-1214 a local or remote vulnerability?
CVE-2009-1214 is considered a local vulnerability, as it requires local access to exploit.