cbcvebase.
CVE-2009-1214
published 2009-04-01

CVE-2009-1214: GNU screen 4.0.3 creates the /tmp/screen-exchange temporary file with world-readable permissions, which might allow local users to obtain sensitive session…

PriorityP410medium4.9CVSS 2.0
AVLACLAuNCCINAN
EPSS
0.34%
26.5th percentile
GNU screen 4.0.3 creates the /tmp/screen-exchange temporary file with world-readable permissions, which might allow local users to obtain sensitive session information.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianscreen< screen 4.0.3-13 (bookworm)screen 4.0.3-13 (bookworm)
gnuscreen
gnuscreen>= 0 < 4.0.3-134.0.3-13
gnuscreen>= 0 < 4.0.3-134.0.3-13
gnuscreen>= 0 < 4.0.3-134.0.3-13
gnuscreen>= 0 < 4.0.3-134.0.3-13

CVSS provenance

nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:C/I:N/A:N
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.