Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2005-4890

Опубликовано: 04 нояб. 2019
Источник: debian
EPSS Низкий

Описание

There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into the input buffer to be read by the next process.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
shadowfixed1:4.1.5-1package
shadowno-dsasqueezepackage
shadowno-dsalennypackage
sudofixed1.7.4p4package

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=173008

  • sudo might be fixed earlier, use_pty present in stable. Only since 1.9.6-1~exp2

  • use_pty is added to default configuration.

EPSS

Процентиль: 38%
0.00163
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 6 лет назад

There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into the input buffer to be read by the next process.

redhat
около 21 года назад

There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into the input buffer to be read by the next process.

CVSS3: 7.8
nvd
почти 6 лет назад

There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into the input buffer to be read by the next process.

CVSS3: 7.8
github
больше 3 лет назад

There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into the input buffer to be read by the next process.

EPSS

Процентиль: 38%
0.00163
Низкий