CVE-2005-4890
7.8
HIGH
CVSS 3.1
EPSS 0.23%
Description
There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into the input buffer to be read by the next process.
How to fix CVE-2005-4890
To remediate CVE-2005-4890, upgrade the affected package to a fixed version below.
- Debian/shadow—upgrade to 1:4.1.5-1 or later
- —upgrade to 1.7.4p4 or later
Is CVE-2005-4890 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 1:4.1.5-1
- from 0, < 1.7.4p4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |