LWN.net Logo

coreutils: command injection

Package(s):coreutils CVE #(s):CVE-2005-4890
Created:May 15, 2012 Updated:May 16, 2012
Description: From the openSUSE advisory:

when running "su -c" to execute commands as different user the target user could inject command back into the calling user's terminal via the TIOCSTI ioctl.

Alerts:
openSUSE openSUSE-SU-2012:0621-1 2012-05-15

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds