There is a possible tty hijacking in shadow 4.x before 4...
High severity
Unreviewed
Published
Apr 21, 2022
to the GitHub Advisory Database
•
Updated Feb 28, 2024
Description
Published by the National Vulnerability Database
Nov 4, 2019
Published to the GitHub Advisory Database
Apr 21, 2022
Last updated
Feb 28, 2024
There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into the input buffer to be read by the next process.
References