There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into the input buffer to be read by the next process.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2019-11-04T18:38:09

Updated: 2019-11-04T18:38:09

Reserved: 2011-12-19T00:00:00


Link: CVE-2005-4890

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-11-04T19:15:10.130

Modified: 2020-08-18T15:05:49.313


Link: CVE-2005-4890

JSON object: View

cve-icon Redhat Information

No data.

CWE