Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-28068 | For a short time they PTY is set to mode 666, allowing any user on the system to connect to the screen session. |
Ubuntu USN |
USN-7978-1 | GNU Screen vulnerabilities |
Tue, 27 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 27 May 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-732 |
Mon, 26 May 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Screen, allowing TTY hijacking during attachment to a multiuser session. The issue with this temporary TTY mode change is that it introduces a race condition that allows any other user in the system to open the caller's TTY for reading and writing for a small period of time. | For a short time they PTY is set to mode 666, allowing any user on the system to connect to the screen session. |
| Title | screen: TTY Hijacking while Attaching to a Multiuser Session | Temporary chown() of users' TTY to mode 0666 allows PTY hijacking in screen |
| References |
| |
| Metrics |
cvssV3_1
|
cvssV4_0
|
Wed, 14 May 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Screen, allowing TTY hijacking during attachment to a multiuser session. The issue with this temporary TTY mode change is that it introduces a race condition that allows any other user in the system to open the caller's TTY for reading and writing for a small period of time. | |
| Title | screen: TTY Hijacking while Attaching to a Multiuser Session | |
| Weaknesses | CWE-362 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: suse
Published:
Updated: 2025-05-27T14:11:53.805Z
Reserved: 2025-04-30T11:28:04.727Z
Link: CVE-2025-46802
Updated: 2025-05-27T14:11:11.940Z
Status : Deferred
Published: 2025-05-26T16:15:20.557
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-46802
OpenCVE Enrichment
Updated: 2025-06-23T19:31:58Z
EUVD
Ubuntu USN