Vulnerabilities
Vulnerable Software
Debian:  >> Shadow  >> 4.0.18.1  Security Vulnerabilities
There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into the input buffer to be read by the next process.
CVSS Score
7.8
EPSS Score
0.002
Published
2019-11-04
/bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utmp group to overwrite arbitrary files via a symlink attack on a temporary file referenced in a line (aka ut_line) field in a utmp entry.
CVSS Score
7.2
EPSS Score
0.001
Published
2008-12-09


Contact Us

Shodan ® - All rights reserved