CVE-2005-4890
CVE-2005-4890
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS —EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
04 nov 2019Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into the input buffer to be read by the next process.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://access.redhat.com/security/cve/cve-2005-4890https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2005-4890https://security-tracker.debian.org/tracker/CVE-2005-4890http://www.openwall.com/lists/oss-security/2012/11/06/8http://www.openwall.com/lists/oss-security/2013/05/20/3http://www.openwall.com/lists/oss-security/2013/11/28/10http://www.openwall.com/lists/oss-security/2013/11/29/5http://www.openwall.com/lists/oss-security/2014/10/20/9http://www.openwall.com/lists/oss-security/2014/10/21/1http://www.openwall.com/lists/oss-security/2014/12/15/5http://www.openwall.com/lists/oss-security/2016/02/25/6