Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Thu, 28 Nov 2013 12:41:49 +0100
From: Salvatore Bonaccorso <>
Subject: CVE Request: adequate: privilege escalation via tty hijacking

Hi Kurt,

I would like to request a CVE for an issue with 'adequate': (adequate: privilege escalation via tty

Package: adequate
Version: 0.4
Severity: serious
Tags: security
Justification: user security hole

If root uses the --user option, then the user can hijack the tty with
TIOCSTI ioctl.

This is similar to CVE-2005-4890.

Jakub Wilk

Fix for this was commited at:

Could a CVE be assigned to this issue?


Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.