CVE-2005-1831 Information

Description

LICENSE README.md cvefilelist cvelist nvdcve nvdpages.sh scripts test-CVE-2017-1882.markdown test-CVE-2017-18822.markdown tmpvendorlinks DISPUTED LICENSE README.md cvefilelist cvelist nvdcve nvdpages.sh scripts test-CVE-2017-1882.markdown test-CVE-2017-18822.markdown tmpvendorlinks Sudo 1.6.8p7 on SuSE Linux 9.3 and possibly other Linux distributions allows local users to gain privileges by using sudo to call su then entering a blank password and hitting CTRL-C. NOTE: SuSE and multiple third-party researchers have not been able to replicate this issue stating \Sudo catches SIGINT and returns an empty string for the password so I don’t see how this could happen unless the user’s actual password was empty.\

Reference

http://archives.neohapsis.com/archives/bugtraq/2005-05/0349.html http://archives.neohapsis.com/archives/bugtraq/2005-05/0359.html http://marc.info/?l=bugtraq&m=111755694008928&w=2 http://www.osvdb.org/20417

Share on: