FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2008-1845

This CVE name corresponds to:

Entered Topic
2008-04-25 mksh -- TTY attachment privilege escalation

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2008-1845
Phase Assigned(20080416)

Description

The Korn shell (aka mksh) before R33d on MirOS (aka MirBSD) does not flush the tty's I/O when invoking mksh in a new terminal, which allows local users to gain privileges by opening a virtual terminal and entering command sequences, which might later be executed in opportunistic circumstances by a different user who launches mksh and specifies that terminal with the -T option.

References

Source Reference
CONFIRM http://www.mirbsd.org/mksh.htm#clog
BID 28768
OSVDB 44365
SECUNIA 29803
XF mirbsd-tty-privilege-escalation(41794)