4.9
CVSSv2

CVE-2009-1214

Published: 01/04/2009 Updated: 17/08/2017
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
VMScore: 436
Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

GNU screen 4.0.3 creates the /tmp/screen-exchange temporary file with world-readable permissions, which might allow local users to obtain sensitive session information.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnu screen 4.0.3

Vendor Advisories

Debian Bug report logs - #521123 /tmp/screen-exchange still unsafe Package: screen; Maintainer for screen is Axel Beckert <abe@debianorg>; Source for screen is src:screen (PTS, buildd, popcon) Reported by: Kees Cook <kees@debianorg> Date: Wed, 25 Mar 2009 00:36:01 UTC Severity: normal Tags: security Found in vers ...