CVE-2005-1831: High severity todd miller sudo vulnerability
DISPUTED Sudo 1.6.8p7 on SuSE Linux 9.3, and possibly other Linux distributions, allows local users to gain privileges by using sudo to call su, then entering a blank password and hitting CTRL-C. NOTE: SuSE and multiple third-party researchers have not been able to replicate this issue, stating "Sudo catches SIGINT and returns an empty string for the password so I don't see how this could happen unless the user's actual password was empty."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-1831?
CVE-2005-1831 is disputed, but it suggests a vulnerability that could allow local users to gain elevated privileges.
How do I fix CVE-2005-1831?
To mitigate CVE-2005-1831, users should upgrade to a version of sudo that is not affected.
Who is affected by CVE-2005-1831?
CVE-2005-1831 affects local users on systems running Sudo version 1.6.8p7, particularly those using SuSE Linux 9.3.
What exploit method is described in CVE-2005-1831?
CVE-2005-1831 describes a method where a local user can exploit the system by calling 'su' with a blank password and then aborting with CTRL-C.
Is there a vendor recommendation for CVE-2005-1831?
The vendor, SuSE, has not confirmed this vulnerability, suggesting that further steps may not be actively communicated.