The default mode of pseudo terminals (PTYs) allocated by Screen was changed from 0620 to 0622, thereby allowing anyone to write to any Screen PTYs in the system.
History

Tue, 27 May 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 26 May 2025 16:30:00 +0000

Type Values Removed Values Added
References

Mon, 26 May 2025 15:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in Screen. The default mode for pseudo-terminals (PTYs) allocated by Screen was changed from 0620 to 0622. This vulnerability allows public writes to any PTYs in the system. The default mode of pseudo terminals (PTYs) allocated by Screen was changed from 0620 to 0622, thereby allowing anyone to write to any Screen PTYs in the system.
Title screen: Screen by Default Creates World Writable PTYs Screen creates by default world-writable PTYs
Weaknesses CWE-276
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}

cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N'}


Wed, 14 May 2025 02:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in Screen. The default mode for pseudo-terminals (PTYs) allocated by Screen was changed from 0620 to 0622. This vulnerability allows public writes to any PTYs in the system.
Title screen: Screen by Default Creates World Writable PTYs
Weaknesses CWE-282
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

threat_severity

Important


cve-icon MITRE

Status: PUBLISHED

Assigner: suse

Published: 2025-05-26T15:06:04.339Z

Updated: 2025-05-27T14:12:42.420Z

Reserved: 2025-04-30T11:28:04.728Z

Link: CVE-2025-46803

cve-icon Vulnrichment

Updated: 2025-05-26T16:04:08.726Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-26T15:15:19.910

Modified: 2025-05-28T15:01:30.720

Link: CVE-2025-46803

cve-icon Redhat

Severity : Important

Publid Date: 2025-05-13T16:41:25Z

Links: CVE-2025-46803 - Bugzilla