{"id":"CVE-2023-28339","details":"OpenDoas through 6.8.2, when TIOCSTI is available, allows privilege escalation because of sharing a terminal with the original session. NOTE: TIOCSTI is unavailable in OpenBSD 6.0 and later, and can be made unavailable in the Linux kernel 6.2 and later.","modified":"2026-08-12T14:50:40.854908Z","published":"2023-03-14T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/28xxx/CVE-2023-28339.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/28xxx/CVE-2023-28339.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-28339"},{"type":"REPORT","url":"https://github.com/Duncaen/OpenDoas/issues/106"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/duncaen/opendoas","events":[{"introduced":"0"},{"fixed":"7f0205fe2f06221d76243342d299851f48c2b83c"}],"database_specific":{"cpe":"cpe:2.3:a:opendoas_project:opendoas:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"6.8.2"},{"last_affected":"6.8.2"}],"source":["DESCRIPTION","CPE_RANGE"]}}],"versions":["v6.8.1","v6.8","v6.6.1","v6.6","v6.0","v0.3.2","v0.3.1","v0.3","v0.2","v0.1"],"database_specific":{"vanir_signatures_modified":"2026-08-12T14:50:40Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"226438582451453904082522244073761597401","length":4421},"id":"CVE-2023-28339-7115ead5","signature_type":"Function","signature_version":"v1","source":"https://github.com/duncaen/opendoas/commit/7f0205fe2f06221d76243342d299851f48c2b83c","target":{"file":"doas.c","function":"main"}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/duncaen/opendoas/commit/7f0205fe2f06221d76243342d299851f48c2b83c","target":{"file":"doas.c"},"deprecated":false,"digest":{"line_hashes":["134337381104205371149834042256174123933","240490000281492794839122102025649612068","178507194066844576015403433077282144014"],"threshold":0.9},"id":"CVE-2023-28339-bdc6ab92"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-28339.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}