Vulnerability Description
There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into the input buffer to be read by the next process.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian | Shadow | >= 4.0.0, <= 4.1.5 |
| Sudo Project | Sudo | >= 1.3.0, <= 1.7.4 |
| Debian | Debian Linux | 8.0 |
| Redhat | Enterprise Linux | 4 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2012/11/06/8Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2013/05/20/3Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2013/11/28/10Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2013/11/29/5Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2014/10/20/9Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2014/10/21/1Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2014/12/15/5Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2016/02/25/6ExploitMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/cve-2005-4890Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2005-4890Issue TrackingThird Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2005-4890Third Party Advisory
- http://www.openwall.com/lists/oss-security/2012/11/06/8Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2013/05/20/3Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2013/11/28/10Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2013/11/29/5Mailing ListThird Party Advisory
FAQ
What is CVE-2005-4890?
CVE-2005-4890 is a vulnerability with a CVSS score of 7.8 (HIGH). There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to p...
How severe is CVE-2005-4890?
CVE-2005-4890 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-4890?
Check the references section above for vendor advisories and patch information. Affected products include: Debian Shadow, Sudo Project Sudo, Debian Debian Linux, Redhat Enterprise Linux.