CVE-2009-1214
published 2009-04-01CVE-2009-1214: GNU screen 4.0.3 creates the /tmp/screen-exchange temporary file with world-readable permissions, which might allow local users to obtain sensitive session…
PriorityP410medium4.9CVSS 2.0
AVLACLAuNCCINAN
EPSS
0.34%
26.5th percentile
GNU screen 4.0.3 creates the /tmp/screen-exchange temporary file with world-readable permissions, which might allow local users to obtain sensitive session information.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | screen | < screen 4.0.3-13 (bookworm) | screen 4.0.3-13 (bookworm) |
| gnu | screen | — | — |
| gnu | screen | >= 0 < 4.0.3-13 | 4.0.3-13 |
| gnu | screen | >= 0 < 4.0.3-13 | 4.0.3-13 |
| gnu | screen | >= 0 < 4.0.3-13 | 4.0.3-13 |
| gnu | screen | >= 0 < 4.0.3-13 | 4.0.3-13 |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:C/I:N/A:N
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vfr3-f488-rjr4: GNU screen 4
ghsa_unreviewed·2022-05-02
CVE-2009-1214 [MEDIUM] GHSA-vfr3-f488-rjr4: GNU screen 4
GNU screen 4.0.3 creates the /tmp/screen-exchange temporary file with world-readable permissions, which might allow local users to obtain sensitive session information.
OSV
CVE-2009-1214: GNU screen 4
osv·2009-04-01·CVSS 4.9
CVE-2009-1214 [MEDIUM] CVE-2009-1214: GNU screen 4
GNU screen 4.0.3 creates the /tmp/screen-exchange temporary file with world-readable permissions, which might allow local users to obtain sensitive session information.
Red Hat
screen: Unsafe usage of temporary file
vendor_redhat·2009-01-11·CVSS 4.9
CVE-2009-1214 [MEDIUM] screen: Unsafe usage of temporary file
screen: Unsafe usage of temporary file
GNU screen 4.0.3 creates the /tmp/screen-exchange temporary file with world-readable permissions, which might allow local users to obtain sensitive session information.
Statement: Red Hat does not consider this to be a security issue. Affected file is supposed to be used to exchange information between local system users, therefore open permissions are intentional.
Debian
CVE-2009-1214: screen - GNU screen 4.0.3 creates the /tmp/screen-exchange temporary file with world-read...
vendor_debian·2009·CVSS 4.9
CVE-2009-1214 [MEDIUM] CVE-2009-1214: screen - GNU screen 4.0.3 creates the /tmp/screen-exchange temporary file with world-read...
GNU screen 4.0.3 creates the /tmp/screen-exchange temporary file with world-readable permissions, which might allow local users to obtain sensitive session information.
Scope: local
bookworm: resolved (fixed in 4.0.3-13)
bullseye: resolved (fixed in 4.0.3-13)
forky: resolved (fixed in 4.0.3-13)
sid: resolved (fixed in 4.0.3-13)
trixie: resolved (fixed in 4.0.3-13)
No detection rules found.
No public exploits indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=521123http://savannah.gnu.org/bugs/?25296http://www.openwall.com/lists/oss-security/2009/03/25/7http://www.securityfocus.com/bid/34521https://bugs.launchpad.net/ubuntu/+source/screen/+bug/315993https://bugzilla.redhat.com/show_bug.cgi?id=492104https://exchange.xforce.ibmcloud.com/vulnerabilities/49886http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=521123http://savannah.gnu.org/bugs/?25296http://www.openwall.com/lists/oss-security/2009/03/25/7http://www.securityfocus.com/bid/34521https://bugs.launchpad.net/ubuntu/+source/screen/+bug/315993https://bugzilla.redhat.com/show_bug.cgi?id=492104https://exchange.xforce.ibmcloud.com/vulnerabilities/49886
2009-04-01
Published