UbuntuUpdates.org

Package "screen"

Name: screen

Description:

terminal multiplexer with VT100/ANSI terminal emulation

Latest version: 4.9.1-1ubuntu1
Release: noble (24.04)
Level: updates
Repository: main
Homepage: https://savannah.gnu.org/projects/screen

Links


Download "screen"


Other versions of "screen" in Noble

Repository Area Version
base main 4.9.1-1build1
security main 4.9.1-1ubuntu1

Changelog

Version: 4.9.1-1ubuntu1 2026-01-27 01:55:58 UTC

  screen (4.9.1-1ubuntu1) noble-security; urgency=medium

  * SECURITY UPDATE: incorrect PTY permissions
    - debian/patches/CVE-2025-46802.patch: prevent temporary 0666 mode on
      PTYs in attacher.c, screen.c.
    - CVE-2025-46802
  * SECURITY UPDATE: minor information leak
    - debian/patches/CVE-2025-46804.patch: avoid file existence test
      information leaks in screen.c, socket.c.
    - CVE-2025-46804
  * SECURITY UPDATE: TOCTOU allowing to send SIGHUP, SIGCONT
    - debian/patches/CVE-2025-46805.patch: don't send signals with root
      privileges in socket.c.
    - CVE-2025-46805

 -- Marc Deslauriers <email address hidden> Thu, 22 Jan 2026 14:59:29 -0500

CVE-2025-46802 For a short time they PTY is set to mode 666, allowing any user on the system to connect to the screen session.
CVE-2025-46804 A minor information leak when running Screen with setuid-root privileges allows unprivileged users to deduce information about a path that would othe
CVE-2025-46805 Screen version 5.0.0 and older version 4 releases have a TOCTOU race potentially allowing to send SIGHUP, SIGCONT to privileged processes when insta



About   -   Send Feedback to @ubuntu_updates