There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into the input buffer to be read by the next process.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade sudoUpgrade shadow | Jul 30, 2024 | Nov 4, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 4, 2019 |
| Suse | — | Upgrade coreutils-x86Upgrade coreutilsUpgrade coreutils-debuginfoUpgrade coreutils-debuginfo-x86Upgrade coreutils-debugsourceUpgrade coreutils-lang | Dec 12, 2013 | Dec 10, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub