CVE-2005-4890 Vulnerability Details

  /     /     /  

CVE-2005-4890 Metadata Quick Info

CVE Published: 04/11/2019 | CVE Updated: 08/08/2024 | CVE Year: 2005
Source: redhat | Vendor: Red Hat | Product: shadow
Status : PUBLISHED

CVE-2005-4890 Description

There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into the input buffer to be read by the next process.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: tty hijacking possible in "su" via TIOCSTI ioctl
Source: Red Hat

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).