CVE-2005-4890
HIGHShadow <4.1.5, Sudo <1.7.4 - Privilege Escalation
Title source: llmDescription
There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into the input buffer to be read by the next process.
References (11)
Scores
CVSS v3
7.8
EPSS
0.0014
EPSS Percentile
33.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-20
Status
published
Affected Products (8)
debian/shadow
< 4.1.5
sudo_project/sudo
< 1.7.4
debian/debian_linux
debian/debian_linux
debian/debian_linux
redhat/enterprise_linux
redhat/enterprise_linux
redhat/enterprise_linux
Timeline
Published
Nov 04, 2019
Tracked Since
Feb 18, 2026