← Back

CVE-2005-1831

nvd nist
Published: May 31, 2005Modified: Apr 16, 2026

JSON object

Loading...
8.4
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.5 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Sudo 1.6.8p7 on SuSE Linux 9.3, and possibly other Linux distributions, allows local users to gain privileges by using sudo to call su, then entering a blank password and hitting CTRL-C. NOTE: SuSE and multiple third-party researchers have not been able to replicate this issue, stating "Sudo catches SIGINT and returns an empty string for the password so I don't see how this could happen unless the user's actual password was empty.

Affected (1)

Products: Todd Miller: Sudo
1 product
Sudo
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.6.8p7

References (8)

Timeline

No history available yet.