CVE-2005-4890

HIGH

Shadow <4.1.5, Sudo <1.7.4 - Privilege Escalation

Title source: llm

Description

There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into the input buffer to be read by the next process.

Scores

CVSS v3 7.8
EPSS 0.0014
EPSS Percentile 33.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-20
Status published

Affected Products (8)

debian/shadow < 4.1.5
sudo_project/sudo < 1.7.4
debian/debian_linux
debian/debian_linux
debian/debian_linux
redhat/enterprise_linux
redhat/enterprise_linux
redhat/enterprise_linux

Timeline

Published Nov 04, 2019
Tracked Since Feb 18, 2026