CVE-2025-46804: Screen 5.0.0 and older versions allow file existence tests when installed setuid-root
Published May 26, 2025
·Updated
A minor information leak when running Screen with setuid-root privileges allows unprivileged users to deduce information about a path that would otherwise not be available.
Affected are older Screen versions, as well as version 5.0.0.
Affected Software
1 affected component
GNU Screen<=5.0.0
Event History
May 26, 2025
CVE Published
via MITRE·01:31 PM
Data Sourced
via MITRE·01:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-46804?
CVE-2025-46804 is considered to be a minor information leak vulnerability.
2
How do I fix CVE-2025-46804?
To fix CVE-2025-46804, update Screen to a version later than 5.0.0.
3
What versions of Screen are affected by CVE-2025-46804?
CVE-2025-46804 affects older versions of Screen as well as version 5.0.0.
4
Can unprivileged users exploit CVE-2025-46804?
Yes, unprivileged users can exploit CVE-2025-46804 to deduce potentially sensitive information.
5
Is CVE-2025-46804 specific to certain operating systems?
CVE-2025-46804 is related to the Screen utility, which can exist across multiple operating systems.