cbcvebase.
CVE-2005-4890
published 2019-11-04

CVE-2005-4890: There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into the input buffer to be read by the next process.

Affected

20 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianshadow< shadow 1:4.1.5-1 (bookworm)shadow 1:4.1.5-1 (bookworm)
debianshadow4.0.0 – 4.1.5
debiansudo< shadow 1:4.1.5-1 (bookworm)shadow 1:4.1.5-1 (bookworm)
red_hatshadow
red_hatsudo
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
shadow_projectshadow>= 0 < 1:4.1.5-11:4.1.5-1
shadow_projectshadow>= 0 < 1:4.1.5-11:4.1.5-1
shadow_projectshadow>= 0 < 1:4.1.5-11:4.1.5-1
shadow_projectshadow>= 0 < 1:4.1.5-11:4.1.5-1
sudo_projectsudo>= 0 < 1.7.4p41.7.4p4
sudo_projectsudo>= 0 < 1.7.4p41.7.4p4
sudo_projectsudo>= 0 < 1.7.4p41.7.4p4
sudo_projectsudo>= 0 < 1.7.4p41.7.4p4
sudo_projectsudo1.3.0 – 1.7.4

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH