High severity7.8NVD Advisory· Published Nov 4, 2019· Updated Jun 16, 2026
CVE-2005-4890
CVE-2005-4890
Description
There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into the input buffer to be read by the next process.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12cpe:2.3:a:sudo_project:sudo:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sudo_project:sudo:*:*:*:*:*:*:*:*range: >=1.3.0,<=1.7.4
- (no CPE)range: <1.7.4
cpe:2.3:o:redhat:enterprise_linux:4:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:redhat:enterprise_linux:4:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:5:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
- Red Hat/shadowv5Range: 4.x before 4.1.5
- Red Hat/sudov5Range: 1.x before 1.7.4
Patches
Vulnerability mechanics
References
11- www.openwall.com/lists/oss-security/2016/02/25/6nvdExploitMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2012/11/06/8nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2013/05/20/3nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2013/11/28/10nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2013/11/29/5nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2014/10/20/9nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2014/10/21/1nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2014/12/15/5nvdMailing ListThird Party Advisory
- access.redhat.com/security/cve/cve-2005-4890nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- security-tracker.debian.org/tracker/CVE-2005-4890nvdThird Party Advisory
News mentions
0No linked articles in our index yet.