CVE Vulnerabilities

CVE-2005-1831

Published: May 31, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Sudo 1.6.8p7 on SuSE Linux 9.3, and possibly other Linux distributions, allows local users to gain privileges by using sudo to call su, then entering a blank password and hitting CTRL-C. NOTE: SuSE and multiple third-party researchers have not been able to replicate this issue, stating Sudo catches SIGINT and returns an empty string for the password so I dont see how this could happen unless the users actual password was empty.

Affected Software

NameVendorStart VersionEnd Version
SudoTodd_miller1.6.8p7 (including)1.6.8p7 (including)

References