CVE-2009-1215
published 2009-04-01CVE-2009-1215: Race condition in GNU screen 4.0.3 allows local users to create or overwrite arbitrary files via a symlink attack on the /tmp/screen-exchange temporary file.
PriorityP47low1.9CVSS 2.0
AVLACMAuNCNIPAN
EPSS
0.23%
14.0th percentile
Race condition in GNU screen 4.0.3 allows local users to create or overwrite arbitrary files via a symlink attack on the /tmp/screen-exchange temporary file.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | screen | < screen 4.0.3-13 (bookworm) | screen 4.0.3-13 (bookworm) |
| gnu | gnu_screen | — | — |
| gnu | screen | >= 0 < 4.0.3-13 | 4.0.3-13 |
| gnu | screen | >= 0 < 4.0.3-13 | 4.0.3-13 |
| gnu | screen | >= 0 < 4.0.3-13 | 4.0.3-13 |
| gnu | screen | >= 0 < 4.0.3-13 | 4.0.3-13 |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:P/A:N
osv1.9LOW
vendor_debian1.9LOW
vendor_redhat1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4mvv-7x66-vcqx: Race condition in GNU screen 4
ghsa_unreviewed·2022-05-02
CVE-2009-1215 [LOW] CWE-362 GHSA-4mvv-7x66-vcqx: Race condition in GNU screen 4
Race condition in GNU screen 4.0.3 allows local users to create or overwrite arbitrary files via a symlink attack on the /tmp/screen-exchange temporary file.
OSV
CVE-2009-1215: Race condition in GNU screen 4
osv·2009-04-01·CVSS 1.9
CVE-2009-1215 [LOW] CVE-2009-1215: Race condition in GNU screen 4
Race condition in GNU screen 4.0.3 allows local users to create or overwrite arbitrary files via a symlink attack on the /tmp/screen-exchange temporary file.
Red Hat
screen: Unsafe usage of temporary file
vendor_redhat·2009-01-11·CVSS 1.9
CVE-2009-1215 [LOW] screen: Unsafe usage of temporary file
screen: Unsafe usage of temporary file
Race condition in GNU screen 4.0.3 allows local users to create or overwrite arbitrary files via a symlink attack on the /tmp/screen-exchange temporary file.
Statement: Red Hat does not consider this to be a security issue. The checks implemented by screen to protect against race condition attacks on /tmp/screen-exchange file provide sufficient protection for this rarely-used buffer exchange feature. For more details, see https://bugzilla.redhat.com/show_bug.cgi?id=492104
Debian
CVE-2009-1215: screen - Race condition in GNU screen 4.0.3 allows local users to create or overwrite arb...
vendor_debian·2009·CVSS 1.9
CVE-2009-1215 [LOW] CVE-2009-1215: screen - Race condition in GNU screen 4.0.3 allows local users to create or overwrite arb...
Race condition in GNU screen 4.0.3 allows local users to create or overwrite arbitrary files via a symlink attack on the /tmp/screen-exchange temporary file.
Scope: local
bookworm: resolved (fixed in 4.0.3-13)
bullseye: resolved (fixed in 4.0.3-13)
forky: resolved (fixed in 4.0.3-13)
sid: resolved (fixed in 4.0.3-13)
trixie: resolved (fixed in 4.0.3-13)
No detection rules found.
No public exploits indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=521123http://savannah.gnu.org/bugs/?25296http://www.openwall.com/lists/oss-security/2009/03/25/7http://www.securityfocus.com/bid/34521https://bugs.launchpad.net/ubuntu/+source/screen/+bug/315993https://bugzilla.redhat.com/show_bug.cgi?id=492104https://exchange.xforce.ibmcloud.com/vulnerabilities/49887http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=521123http://savannah.gnu.org/bugs/?25296http://www.openwall.com/lists/oss-security/2009/03/25/7http://www.securityfocus.com/bid/34521https://bugs.launchpad.net/ubuntu/+source/screen/+bug/315993https://bugzilla.redhat.com/show_bug.cgi?id=492104https://exchange.xforce.ibmcloud.com/vulnerabilities/49887
2009-04-01
Published