{"id":"CVE-2025-23395","details":"Screen 5.0.0 when it runs with setuid-root privileges does not drop privileges while operating on a user supplied path. This allows unprivileged users to create files in arbitrary locations with `root` ownership, the invoking user's (real) group ownership and file mode 0644. All data written to the Screen PTY will be logged into this file, allowing to escalate to root privileges","modified":"2026-04-10T05:22:53.950849Z","published":"2025-05-26T16:15:20Z","references":[{"type":"REPORT","url":"https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-23395"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2025/05/12/1"}],"schema_version":"1.7.5"}