NA

CVE-2023-28339

Published: 14/03/2023 Updated: 21/03/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

OpenDoas up to and including 6.8.2, when TIOCSTI is available, allows privilege escalation because of sharing a terminal with the original session. NOTE: TIOCSTI is unavailable in OpenBSD 6.0 and later, and can be made unavailable in the Linux kernel 6.2 and later.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

opendoas project opendoas

Vendor Advisories

Debian Bug report logs - #1034185 opendoas: CVE-2023-28339 Package: src:opendoas; Maintainer for src:opendoas is Scupake <scupake@riseupnet>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Mon, 10 Apr 2023 17:45:06 UTC Severity: important Tags: security, upstream Forwarded to githubcom/Duncaen/O ...