[Bug 9401] privilege escalation with TIOCSTI ioctl from busybox su

bugzilla at busybox.net bugzilla at busybox.net
Fri Nov 4 00:05:05 UTC 2016


https://bugs.busybox.net/show_bug.cgi?id=9401

--- Comment #3 from Lizzie Dixon <_ at lizzie.io> ---
> However, this only works interactively, when root runs "su lizzie -c ./tiocsti" from a command line shell. This will not work from a script, when stdin is not used for command input.

Yes, this is true. Sorry, should have added a note about that.

> In practice, not having controlling tty is at times a serious inconvenience.

Could you explain what inconveniences you're thinking of?

-- 
You are receiving this mail because:
You are on the CC list for the bug.


More information about the busybox-cvs mailing list