Description
OpenDoas through 6.8.2, when TIOCSTI is available, allows privilege escalation because of sharing a terminal with the original session. NOTE: TIOCSTI is unavailable in OpenBSD 6.0 and later, and can be made unavailable in the Linux kernel 6.2 and later.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-32037 | OpenDoas through 6.8.2, when TIOCSTI is available, allows privilege escalation because of sharing a terminal with the original session. NOTE: TIOCSTI is unavailable in OpenBSD 6.0 and later, and can be made unavailable in the Linux kernel 6.2 and later. |
References
| Link | Providers |
|---|---|
| https://github.com/Duncaen/OpenDoas/issues/106 |
|
History
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Feb 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-269 |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-27T19:38:37.401Z
Reserved: 2023-03-14T00:00:00.000Z
Link: CVE-2023-28339
Updated: 2024-08-02T12:38:25.003Z
Status : Modified
Published: 2023-03-14T19:15:10.717
Modified: 2025-02-27T20:15:37.613
Link: CVE-2023-28339
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD